Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

Antwort
Alt 21.07.2014, 12:03   #16
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 21.07.2014, 13:12   #17
pilimen400
 
Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Combofix hatte über Spybot gemeckert. Habe den Echtzeitschutz deaktiviert, dann gab es keine Probleme mehr.

Während Combofix gearbeitet habe, bin ich aus Versehen auf den Hotkey auf der Tastatur gekommen, welches Google Chrome startet. Hoffentlich hat dies nichts beeinflusst.


P.S.: Antivir lässt sich immer noch nicht starten und ich habe heute eine Mail von Playpal bekommen. Darin steht, dass mein Konto aufgrund eines Betrugsversuchs gesperrt wurde!

Code:
ATTFilter
ComboFix 14-07-20.02 - ********** 21.07.2014  13:31:15.1.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1251.7.1031.18.8130.5175 [GMT 2:00]
Running from: c:\users\**********\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Created a new restore point
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\**********\AppData\Local\assembly\tmp
c:\users\**********\AppData\Local\Temp\_MEI29082\_ctypes.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_elementtree.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_hashlib.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_multiprocessing.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_socket.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_ssl.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\hashobjs_ext.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\pyexpat.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\pysqlite2._sqlite.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\python27.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\pythoncom27.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\PyWinTypes27.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\select.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\unicodedata.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32api.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32com.shell.shell.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32crypt.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32event.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32file.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32gui.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32inet.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32pdh.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32pipe.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32process.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32profile.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32security.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32ts.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\windows._lib_cacheinvalidation.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._animate.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._controls_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._core_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._gdi_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._html2.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._misc_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._windows_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._wizard.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wxbase294u_net_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxbase294u_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_adv_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_core_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_html_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_webview_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\_ctypes.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_elementtree.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_hashlib.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_multiprocessing.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_socket.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\_ssl.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\hashobjs_ext.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\pyexpat.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\pysqlite2._sqlite.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\python27.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\pythoncom27.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\PyWinTypes27.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\select.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\unicodedata.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32api.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32com.shell.shell.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32crypt.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32event.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32file.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32gui.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32inet.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32pdh.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32pipe.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32process.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32profile.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32security.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\win32ts.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\windows._lib_cacheinvalidation.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._animate.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._controls_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._core_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._gdi_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._html2.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._misc_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._windows_.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wx._wizard.pyd
c:\users\**********\AppData\Local\Temp\_MEI29082\wxbase294u_net_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxbase294u_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_adv_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_core_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_html_vc90.dll
c:\users\**********\AppData\Local\Temp\_MEI29082\wxmsw294u_webview_vc90.dll
c:\windows\IsUn0407.exe
c:\windows\SysWow64\tmp4F3A.tmp
c:\windows\SysWow64\tmp4F4A.tmp
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_ACEDRV11
-------\Service_acedrv11
.
.
(((((((((((((((((((((((((   Files Created from 2014-06-21 to 2014-07-21  )))))))))))))))))))))))))))))))
.
.
2014-07-21 11:50 . 2014-07-21 11:50	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-07-20 20:25 . 2014-07-20 20:25	--------	d-----w-	c:\program files (x86)\DSDCS
2014-07-19 21:38 . 2014-07-19 21:38	--------	d-----w-	c:\program files (x86)\VS Revo Group
2014-07-19 10:54 . 2014-07-02 03:09	10924376	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{8C943139-9AA7-4AB5-A741-95E080986D7F}\mpengine.dll
2014-07-18 23:26 . 2014-07-18 23:26	--------	d-----w-	C:\FRST
2014-07-18 23:21 . 2014-07-18 23:21	--------	d-----w-	C:\found.005
2014-07-18 21:14 . 2014-07-18 21:14	--------	d-----w-	C:\found.004
2014-07-17 12:08 . 2014-07-17 12:08	--------	d-----w-	C:\found.003
2014-07-16 17:44 . 2014-07-16 17:44	--------	d-----w-	c:\program files (x86)\NirSoft
2014-07-16 15:05 . 2014-07-16 15:05	--------	d-----w-	C:\found.002
2014-07-16 14:51 . 2014-07-16 14:51	--------	d-----w-	C:\found.001
2014-07-15 10:43 . 2014-07-20 10:37	163504	----a-w-	c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
2014-07-10 13:29 . 2014-07-19 11:26	--------	d-----w-	c:\users\**********\AppData\Local\Arma 3
2014-07-10 13:29 . 2014-07-10 13:29	--------	d-----w-	c:\programdata\Bohemia Interactive
2014-07-09 10:18 . 2014-06-20 20:14	810160	----a-w-	c:\program files\Internet Explorer\iexplore.exe
2014-07-06 21:52 . 2014-04-18 15:02	74432	----a-w-	c:\windows\system32\drivers\RzFilter.sys
2014-07-06 21:52 . 2014-04-18 15:02	129472	----a-w-	c:\windows\system32\drivers\RzDxgk.sys
2014-07-06 21:34 . 2014-07-06 21:34	43152	----a-w-	c:\windows\avastSS.scr
2014-07-06 21:18 . 2014-07-06 21:18	--------	d-----w-	C:\found.000
2014-07-01 21:45 . 2014-07-01 22:00	--------	d-----w-	c:\users\**********\AppData\Roaming\SpinTires
2014-06-28 00:21 . 2014-06-28 00:21	--------	d-----w-	c:\users\**********\AppData\Local\Sniper3
2014-06-25 18:30 . 2014-06-25 18:30	--------	d-----w-	c:\program files\Microsoft Xbox One Controller for Windows
2014-06-24 01:09 . 2014-06-24 01:09	--------	d-----w-	c:\users\**********\AppData\Local\Oblivion
2014-06-24 00:31 . 2014-06-24 00:31	--------	d-sh--w-	c:\programdata\SecuROM
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-07-19 21:11 . 2009-08-18 11:49	564632	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2014-07-19 21:11 . 2009-08-18 10:24	23256	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-07-09 14:26 . 2011-12-19 19:02	96441528	----a-w-	c:\windows\system32\MRT.exe
2014-07-08 23:56 . 2012-04-03 17:41	699056	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-07-08 23:56 . 2011-12-17 02:09	71344	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-07-06 21:34 . 2013-09-15 20:37	427360	----a-w-	c:\windows\system32\drivers\aswsp.sys
2014-07-06 21:34 . 2014-04-19 18:37	29208	----a-w-	c:\windows\system32\drivers\aswHwid.sys
2014-07-06 21:34 . 2013-12-19 06:52	92008	----a-w-	c:\windows\system32\drivers\aswstm.sys
2014-07-06 21:34 . 2013-09-15 20:37	93568	----a-w-	c:\windows\system32\drivers\aswRdr2.sys
2014-07-06 21:34 . 2013-09-15 20:37	79184	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
2014-07-06 21:34 . 2013-09-15 20:37	65776	----a-w-	c:\windows\system32\drivers\aswRvrt.sys
2014-07-06 21:34 . 2013-09-15 20:37	224896	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2014-07-06 21:34 . 2013-09-15 20:37	1041168	----a-w-	c:\windows\system32\drivers\aswsnx.sys
2014-07-06 21:34 . 2011-12-17 00:03	307344	----a-w-	c:\windows\system32\aswBoot.exe
2014-05-29 23:00 . 2014-06-18 12:39	1291232	----a-w-	c:\windows\SysWow64\nvspbridge.dll
2014-05-29 23:00 . 2014-06-18 12:39	1122312	----a-w-	c:\windows\SysWow64\nvspcap.dll
2014-05-29 22:59 . 2014-06-18 12:39	1715176	----a-w-	c:\windows\system32\nvspbridge64.dll
2014-05-29 22:59 . 2014-06-18 12:39	1279480	----a-w-	c:\windows\system32\nvspcap64.dll
2014-05-29 05:32 . 2014-05-29 05:32	80384	----a-w-	c:\windows\system32\RazerCoinstaller.dll
2014-05-26 23:13 . 2014-05-26 23:13	34016	----a-w-	c:\windows\system32\drivers\xb1usb.sys
2014-05-24 02:33 . 2014-05-24 02:33	864256	----a-w-	c:\windows\SysWow64\rzdevicedll.dll
2014-05-24 02:33 . 2014-05-24 02:33	325120	----a-w-	c:\windows\SysWow64\rzaudiodll.dll
2014-05-20 02:44 . 2014-06-18 12:45	9735256	----a-w-	c:\windows\SysWow64\nvcuda.dll
2014-05-20 02:44 . 2014-06-18 12:45	9697640	----a-w-	c:\windows\SysWow64\nvopencl.dll
2014-05-20 02:44 . 2014-06-18 12:45	895776	----a-w-	c:\windows\system32\NvIFR64.dll
2014-05-20 02:44 . 2014-06-18 12:45	892704	----a-w-	c:\windows\system32\NvFBC64.dll
2014-05-20 02:44 . 2014-06-18 12:45	867784	----a-w-	c:\windows\SysWow64\NvIFR.dll
2014-05-20 02:44 . 2014-06-18 12:45	861128	----a-w-	c:\windows\SysWow64\NvFBC.dll
2014-05-20 02:44 . 2014-06-18 12:45	837056	----a-w-	c:\windows\SysWow64\nvumdshim.dll
2014-05-20 02:44 . 2014-06-18 12:45	492376	----a-w-	c:\windows\system32\nvEncodeAPI64.dll
2014-05-20 02:44 . 2014-06-18 12:45	416712	----a-w-	c:\windows\SysWow64\nvEncodeAPI.dll
2014-05-20 02:44 . 2014-06-18 12:45	382240	----a-w-	c:\windows\system32\NvIFROpenGL.dll
2014-05-20 02:44 . 2014-06-18 12:45	354016	----a-w-	c:\windows\system32\nvoglshim64.dll
2014-05-20 02:44 . 2014-06-18 12:45	335704	----a-w-	c:\windows\SysWow64\NvIFROpenGL.dll
2014-05-20 02:44 . 2014-06-18 12:45	32544	----a-w-	c:\windows\system32\drivers\nvpciflt.sys
2014-05-20 02:44 . 2014-06-18 12:45	3141976	----a-w-	c:\windows\system32\nvcuvid.dll
2014-05-20 02:44 . 2014-06-18 12:45	31387936	----a-w-	c:\windows\system32\nvoglv64.dll
2014-05-20 02:44 . 2014-06-18 12:45	305600	----a-w-	c:\windows\SysWow64\nvoglshim32.dll
2014-05-20 02:44 . 2014-06-18 12:45	2953672	----a-w-	c:\windows\SysWow64\nvcuvid.dll
2014-05-20 02:44 . 2014-06-18 12:45	2785568	----a-w-	c:\windows\system32\nvcuvenc.dll
2014-05-20 02:44 . 2014-06-18 12:45	25256224	----a-w-	c:\windows\system32\nvcompiler.dll
2014-05-20 02:44 . 2014-06-18 12:45	2412376	----a-w-	c:\windows\SysWow64\nvcuvenc.dll
2014-05-20 02:44 . 2014-06-18 12:45	24025376	----a-w-	c:\windows\SysWow64\nvoglv32.dll
2014-05-20 02:44 . 2014-06-18 12:45	1889112	----a-w-	c:\windows\system32\nvdispco6433788.dll
2014-05-20 02:44 . 2014-06-18 12:45	17561544	----a-w-	c:\windows\SysWow64\nvcompiler.dll
2014-05-20 02:44 . 2014-06-18 12:45	166568	----a-w-	c:\windows\system32\nvinitx.dll
2014-05-20 02:44 . 2014-06-18 12:45	16003912	----a-w-	c:\windows\SysWow64\nvwgf2um.dll
2014-05-20 02:44 . 2014-06-18 12:45	1541576	----a-w-	c:\windows\system32\nvdispgenco6433788.dll
2014-05-20 02:44 . 2014-06-18 12:45	146480	----a-w-	c:\windows\SysWow64\nvinit.dll
2014-05-20 02:44 . 2014-06-18 12:45	12688328	----a-w-	c:\windows\system32\drivers\nvlddmkm.sys
2014-05-20 02:44 . 2014-06-18 12:45	11644928	----a-w-	c:\windows\system32\nvcuda.dll
2014-05-20 02:44 . 2014-06-18 12:45	11599072	----a-w-	c:\windows\system32\nvopencl.dll
2014-05-20 02:44 . 2014-03-14 13:35	61216	----a-w-	c:\windows\system32\OpenCL.dll
2014-05-20 02:44 . 2014-03-14 13:35	52056	----a-w-	c:\windows\SysWow64\OpenCL.dll
2014-05-20 02:44 . 2014-03-08 19:34	952952	----a-w-	c:\windows\system32\nvumdshimx.dll
2014-05-20 02:44 . 2014-03-08 19:34	18531568	----a-w-	c:\windows\system32\nvwgf2umx.dll
2014-05-20 02:44 . 2014-03-08 19:34	17480432	----a-w-	c:\windows\system32\nvd3dumx.dll
2014-05-20 02:44 . 2014-03-08 19:34	14434704	----a-w-	c:\windows\SysWow64\nvd3dum.dll
2014-05-20 02:44 . 2014-03-08 19:34	3109248	----a-w-	c:\windows\system32\nvapi64.dll
2014-05-20 02:44 . 2014-03-08 19:34	2730208	----a-w-	c:\windows\SysWow64\nvapi.dll
2014-05-20 01:25 . 2014-03-14 13:51	6769096	----a-w-	c:\windows\system32\nvcpl.dll
2014-05-20 01:25 . 2014-03-14 13:51	3514144	----a-w-	c:\windows\system32\nvsvc64.dll
2014-05-20 01:25 . 2014-03-14 13:51	927520	----a-w-	c:\windows\system32\nvvsvc.exe
2014-05-20 01:25 . 2014-04-07 18:14	76064	----a-w-	c:\windows\system32\nv3dappshextr.dll
2014-05-20 01:25 . 2014-04-07 18:14	1078616	----a-w-	c:\windows\system32\nv3dappshext.dll
2014-05-20 01:25 . 2014-03-14 13:51	62808	----a-w-	c:\windows\system32\nvshext.dll
2014-05-20 01:25 . 2014-03-14 13:51	387528	----a-w-	c:\windows\system32\nvmctray.dll
2014-05-20 01:25 . 2014-03-14 13:51	2560968	----a-w-	c:\windows\system32\nvsvcr.dll
2014-05-19 23:10 . 2014-06-18 12:46	601432	----a-w-	c:\windows\SysWow64\nvStreaming.exe
2014-05-19 06:47 . 2014-05-19 06:47	39080	----a-w-	c:\windows\system32\drivers\rzendpt.sys
2014-05-19 06:47 . 2014-05-19 06:47	34984	----a-w-	c:\windows\system32\drivers\rzmpos.sys
2014-05-19 06:47 . 2014-05-19 06:47	155816	----a-w-	c:\windows\system32\drivers\rzudd.sys
2014-05-19 06:26 . 2014-05-19 06:26	89088	----a-w-	c:\windows\SysWow64\rzdevinfo.dll
2014-05-19 06:26 . 2014-05-19 06:26	155136	----a-w-	c:\windows\SysWow64\rztouchdll.dll
2014-05-19 06:26 . 2014-05-19 06:26	117248	----a-w-	c:\windows\SysWow64\rzdisplaydll.dll
2014-05-14 23:49 . 2014-03-14 13:51	3774821	----a-w-	c:\windows\system32\nvcoproc.bin
2014-05-10 08:11 . 2014-05-10 08:11	1795952	----a-w-	c:\windows\system32\drivers\WdfCoInstaller01011.dll
2014-05-08 09:32 . 2014-06-11 11:07	3178496	----a-w-	c:\windows\system32\rdpcorets.dll
2014-05-08 09:32 . 2014-06-11 11:07	16384	----a-w-	c:\windows\system32\RdpGroupPolicyExtension.dll
2014-04-25 02:34 . 2014-06-11 11:07	801280	----a-w-	c:\windows\system32\usp10.dll
2014-04-25 02:06 . 2014-06-11 11:07	626688	----a-w-	c:\windows\SysWow64\usp10.dll
2013-10-14 02:44 . 2013-10-14 02:44	2174976	----a-w-	c:\program files (x86)\Common Files\atimpenc.dll
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-06-20 21:24	233120	----a-w-	c:\users\**********\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-06-20 21:24	233120	----a-w-	c:\users\**********\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-06-20 21:24	233120	----a-w-	c:\users\**********\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\SkyDriveShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	131248	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Steam"="e:\games\Steam\steam.exe" [2014-07-16 1753280]
"Windows Remote Service"="c:\program files (x86)\Banamalon\Windows Remote Service\WindowsRemoteService.exe" [2013-04-18 172544]
"GoogleDriveSync"="c:\program files (x86)\Google\Drive\googledrivesync.exe" [2014-06-27 24477056]
"DAEMON Tools Ultra Agent"="c:\program files (x86)\DAEMON Tools Ultra\DTAgent.exe" [2013-06-25 3128352]
"Spybot-S&D Cleaning"="c:\program files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" [2013-05-16 3642312]
"SkyDrive"="c:\users\**********\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" [2014-06-20 251048]
"DS4Tool"="c:\program files (x86)\DSDCS\DS4Tool\DS4Tool.exe" [2014-07-19 3021312]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
"SDTray"="c:\program files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [2013-07-25 5624784]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-07-06 4086432]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2013-04-26 292848]
"Razer Synapse"="c:\program files (x86)\Razer\Synapse\RzSynapse.exe" [2014-06-23 585560]
.
c:\users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\**********\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-5-20 33322312]
Monitor.lnk - c:\users\**********\AppData\Roaming\Realtime Soft\UltraMon\3.2.2\Profiles\Monitor.umprofile [2012-12-29 377]
Samsung Magician.lnk - c:\windows\system32\schtasks.exe  /run /tn SamsungMagician [2010-11-21 285696]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
UltraMon.lnk - c:\windows\Installer\{9069EE0A-7615-4D86-AD80-CA263E936DA6}\IcoUltraMon.ico /auto [2012-12-29 29310]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute	REG_MULTI_SZ   	autocheck autochk *\0sdnclean64.exe
.
R1 ASMTFilter;Asmedia  Upper Filter Driver;c:\windows\system32\DRIVERS\asmtufdriver.sys;c:\windows\SYSNATIVE\DRIVERS\asmtufdriver.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 CsrBtOBEX-Dienst;CSR OBEX-Dienst;c:\program files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe;c:\program files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 AiChargerPlus;AiChargerPlus;SysWow64\drivers\AiChargerPlus.sys;SysWow64\drivers\AiChargerPlus.sys [x]
R3 ASUSFILTER;ASUSFILTER;SysWow64\drivers\ASUSFILTER.sys;SysWow64\drivers\ASUSFILTER.sys [x]
R3 ATHDFU;Atheros Valkyrie USB BootROM;c:\windows\system32\Drivers\AthDfu.sys;c:\windows\SYSNATIVE\Drivers\AthDfu.sys [x]
R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x]
R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys;c:\windows\SYSNATIVE\DRIVERS\btfilter.sys [x]
R3 CsrBtPort;CSR Bluetooth-Geratetreiber;c:\windows\system32\DRIVERS\CsrBtPort.sys;c:\windows\SYSNATIVE\DRIVERS\CsrBtPort.sys [x]
R3 csrhidmini;Bluetooth HID-Hostprofil;c:\windows\system32\DRIVERS\csrhidmini.sys;c:\windows\SYSNATIVE\DRIVERS\csrhidmini.sys [x]
R3 csrpan;Bluetooth Personal Area Network Device Driver;c:\windows\system32\DRIVERS\csrpan.sys;c:\windows\SYSNATIVE\DRIVERS\csrpan.sys [x]
R3 csrserial;SPP-Geratetreiber;c:\windows\system32\DRIVERS\csrserial.sys;c:\windows\SYSNATIVE\DRIVERS\csrserial.sys [x]
R3 csrusb;CSR USB-Treiber fur Bluetooth-Dongle;c:\windows\system32\Drivers\csrusb.sys;c:\windows\SYSNATIVE\Drivers\csrusb.sys [x]
R3 csrusbfilter;CSR USB filter driver;c:\windows\system32\Drivers\csrusbfilter.sys;c:\windows\SYSNATIVE\Drivers\csrusbfilter.sys [x]
R3 Desura Install Service;Desura Install Service;c:\program files (x86)\Common Files\Desura\desura_service.exe;c:\program files (x86)\Common Files\Desura\desura_service.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
R3 Disc Soft Bus Service;Disc Soft Bus Service;c:\program files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe;c:\program files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\SystemInfo\FMSISvc.exe;c:\program files (x86)\Futuremark\SystemInfo\FMSISvc.exe [x]
R3 GPUZ;GPUZ;c:\windows\TEMP\GPUZ.sys;c:\windows\TEMP\GPUZ.sys [x]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe;c:\program files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface;c:\program files\Intel\iCLS Client\SocketHeciServer.exe;c:\program files\Intel\iCLS Client\SocketHeciServer.exe [x]
R3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys;c:\windows\SYSNATIVE\drivers\LGBusEnum.sys [x]
R3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys;c:\windows\SYSNATIVE\drivers\LGVirHid.sys [x]
R3 libusb0;libusb-win32 - Kernel Driver, Version 1.2.2.0;c:\windows\system32\drivers\libusb0.sys;c:\windows\SYSNATIVE\drivers\libusb0.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RTCore64;RTCore64;c:\program files (x86)\MSI Afterburner\RTCore64.sys;c:\program files (x86)\MSI Afterburner\RTCore64.sys [x]
R3 ssudmdm;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
R3 tapoas;TAP-Win32 Adapter OAS;c:\windows\system32\DRIVERS\tapoas.sys;c:\windows\SYSNATIVE\DRIVERS\tapoas.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x]
R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
R3 vjoy;vJoy Device;c:\windows\system32\DRIVERS\vjoy.sys;c:\windows\SYSNATIVE\DRIVERS\vjoy.sys [x]
R3 xb1usb;Microsoft Xbox One Controller Driver;c:\windows\system32\DRIVERS\xb1usb.sys;c:\windows\SYSNATIVE\DRIVERS\xb1usb.sys [x]
R4 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
R4 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x]
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys;SysWow64\drivers\AsUpIO.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 RzFilter;RzFilter;c:\windows\system32\drivers\RzFilter.sys;c:\windows\SYSNATIVE\drivers\RzFilter.sys [x]
S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe;c:\program files (x86)\Bluetooth Suite\adminservice.exe [x]
S2 c2cautoupdatesvc;Skype Click to Call Updater;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe;c:\program files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [x]
S2 c2cpnrsvc;Skype Click to Call PNR Service;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe;c:\program files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys;c:\windows\SYSNATIVE\drivers\cpuz135_x64.sys [x]
S2 DTSAudioService;DTSAudioService;c:\program files\Realtek\Audio\HDA\DTSAudioService64.exe;c:\program files\Realtek\Audio\HDA\DTSAudioService64.exe [x]
S2 DTSAudioSvc;DTSAudioSvc;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe;c:\program files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;c:\windows\system32\IProsetMonitor.exe;c:\windows\SYSNATIVE\IProsetMonitor.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 Mezzmo;Mezzmo;c:\program files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe;c:\program files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 RzOvlMon;Razer Overlay Subsystem Emergency Service;c:\program files (x86)\Razer\Core\64bit\rzovlmon.exe;c:\program files (x86)\Razer\Core\64bit\rzovlmon.exe [x]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [x]
S2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [x]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe;c:\program files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [x]
S2 SplashtopRemoteService;Splashtop® Remote Service;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe;c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe [x]
S2 SSUService;Splashtop Software Updater Service;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe;c:\program files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [x]
S3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_flt.sys [x]
S3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys;c:\windows\SYSNATIVE\drivers\btath_a2dp.sys [x]
S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys;c:\windows\SYSNATIVE\DRIVERS\btath_bus.sys [x]
S3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_hcrp.sys [x]
S3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys;c:\windows\SYSNATIVE\DRIVERS\btath_lwflt.sys [x]
S3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys;c:\windows\SYSNATIVE\DRIVERS\btath_rcp.sys [x]
S3 dtscsibus;DAEMON Tools Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtscsibus.sys;c:\windows\SYSNATIVE\DRIVERS\dtscsibus.sys [x]
S3 e1dexpress;Intel(R) PRO/1000 PCI Express Network Connection Driver D;c:\windows\system32\DRIVERS\e1d62x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1d62x64.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 NvStreamKms;NvStreamKms;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys;c:\program files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 RzDxgk;RzDxgk;c:\windows\system32\drivers\RzDxgk.sys;c:\windows\SYSNATIVE\drivers\RzDxgk.sys [x]
S3 rzendpt;rzendpt;c:\windows\system32\DRIVERS\rzendpt.sys;c:\windows\SYSNATIVE\DRIVERS\rzendpt.sys [x]
S3 rzmpos;rzmpos;c:\windows\system32\DRIVERS\rzmpos.sys;c:\windows\SYSNATIVE\DRIVERS\rzmpos.sys [x]
S3 rzudd;Razer Mouse Driver;c:\windows\system32\DRIVERS\rzudd.sys;c:\windows\SYSNATIVE\DRIVERS\rzudd.sys [x]
S3 ScpVBus;Scp Virtual Bus Driver;c:\windows\system32\DRIVERS\ScpVBus.sys;c:\windows\SYSNATIVE\DRIVERS\ScpVBus.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-07-19 21:29	1104200	----a-w-	c:\program files (x86)\Google\Chrome\Application\36.0.1985.125\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-07-21 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 23:56]
.
2014-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-17 00:03]
.
2014-07-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-12-17 00:03]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2014-06-20 21:24	260768	----a-w-	c:\users\**********\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2014-06-20 21:24	260768	----a-w-	c:\users\**********\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2014-06-20 21:24	260768	----a-w-	c:\users\**********\AppData\Local\Microsoft\SkyDrive\17.3.1166.0618\amd64\SkyDriveShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-07-06 21:34	634872	----a-w-	c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-09-10 23:54	164016	----a-w-	c:\users\**********\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2014-06-27 12:20	777032	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20	777032	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedEditOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44}]
2014-06-27 12:20	777032	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedViewOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2014-06-27 12:20	777032	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2014-06-27 12:20	777032	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2014-06-27 12:20	777032	----a-w-	c:\program files (x86)\Google\Drive\googledrivesync64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtherosBtStack"="c:\program files (x86)\Bluetooth Suite\BtvStack.exe" [2010-10-27 613536]
"AthBtTray"="c:\program files (x86)\Bluetooth Suite\AthBtTray.exe" [2010-10-27 379040]
"Logitech Download Assistant"="c:\windows\System32\LogiLDA.dll" [2012-09-20 1832760]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-08-19 7202520]
"RtHDVBg_DTS"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2013-08-07 1321688]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-05-29 2350880]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 825184]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-05-29 1279480]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://google.de/
mStart Page = https://de.yahoo.com?fr=hp-avast&type=prc265
mLocal Page = c:\windows\SysWOW64\blank.htm
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\
FF - prefs.js: browser.search.defaulturl - hxxp://de.yhs4.search.yahoo.com/yhs/search
FF - prefs.js: browser.search.selectedEngine - Trovi search
FF - prefs.js: browser.startup.homepage - hxxp://www.trovi.com/?gd=&ctid=CT3318399&octid=EB_ORIGINAL_CTID&ISID=M9D0C5C87-F3FB-4236-ADF7-7845DC4C8DB7&SearchSource=55&CUI=&UM=5&UP=SP622ED464-78BE-4420-8EB7-DEEF1ABE0F62&SSPV=
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKLM-Run-<NO NAME> - (no file)
Notify-SDWinLogon - SDWinLogon.dll
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
AddRemove-BattlEye for OA - e:\games\ArmA 2\Expansion\BattlEye\UnInstallBE.exe
AddRemove-Dark Souls PTDE *UPDATE 1.02*_is1 - c:\dark souls\unins000.exe
AddRemove-Mercenary Kings_is1 - e:\games\Mercenary Kings\unins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_14_0_0_145_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.14"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_14_0_0_145.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
c:\program files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Completion time: 2014-07-21  13:59:45 - machine was rebooted
ComboFix-quarantined-files.txt  2014-07-21 11:59
.
Pre-Run: 14 Verzeichnis(se), 77.121.921.024 Bytes frei
Post-Run: 24 Verzeichnis(se), 76.808.466.432 Bytes frei
.
- - End Of File - - 659D34A029BBE3E767CEA37EC7B6A39B
B1F7D7F6E4FBE98E578562A22A94D02C
         
__________________


Alt 21.07.2014, 14:05   #18
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



wir haben ja auch erst angefangen. Von einem andern rechner alle Passwörter und Zugänge ändern.

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
__________________

Alt 21.07.2014, 20:32   #19
pilimen400
 
Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



mbam.txt:
Code:
ATTFilter
 Malwarebytes Anti-Malware 
www.malwarebytes.org

Suchlauf Datum: 21.07.2014
Suchlauf-Zeit: 20:13:07
Logdatei: mbam.txt
Administrator: Ja

Version: 2.00.2.1012
Malware Datenbank: v2014.07.21.07
Rootkit Datenbank: v2014.07.17.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bosartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: *************

Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 302005
Verstrichene Zeit: 3 Min, 55 Sek

Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registrierungsschlussel: 3
PUP.Optional.RegCleanPro.A, HKLM\SOFTWARE\WOW6432NODE\SYSTWEAK\RegClean Pro, In Quarantane, [78b38d157cffcf67c4fb1bab19e9857b], 
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantane, [33f8faa89ae1d95dd45447a39a6856aa], 
PUP.Optional.Softonic.A, HKU\S-1-5-21-2237465050-2375263089-2847873979-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantane, [5ad12d7588f386b0545e667531d1f30d], 

Registrierungswerte: 1
PUP.Optional.OpinionSquare.A, HKLM\SOFTWARE\WOW6432NODE\MOZILLA\FIREFOX\EXTENSIONS|{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}, C:\Program Files (x86)\RelevantKnowledge\firefox, In Quarantane, [e546cdd5fc7f7db9fa98b71962a01ae6]

Registrierungsdaten: 0
(No malicious items detected)

Ordner: 2
PUP.Optional.OpenCandy, C:\Users\*************\AppData\Roaming\OpenCandy, In Quarantane, [62c9049e1b60d46295ef584c1ae846ba], 
PUP.Optional.OpenCandy, C:\Users\*************\AppData\Roaming\OpenCandy\E336715DE3BD4BF69F369517C69655DF, In Quarantane, [62c9049e1b60d46295ef584c1ae846ba], 

Dateien: 9
PUP.Optional.Conduit.A, C:\Users\*************\AppData\Roaming\OpenCandy\E336715DE3BD4BF69F369517C69655DF\mconduitinstaller.exe, In Quarantane, [f9329f03d5a6bf77962724fa1fe1f907], 
PUP.Optional.Ciuvo.A, C:\Users\*************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\extensions\extension@ciuvo.com.xpi, In Quarantane, [d15ac1e16d0e9a9cfd2c5a6edf238779], 
PUP.Optional.Trovi.A, C:\Users\*************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\trovi-search.xml, In Quarantane, [a4873c66e69578be8dfa874da1617d83], 
PUP.Optional.OpenCandy, C:\Users\*************\AppData\Roaming\OpenCandy\E336715DE3BD4BF69F369517C69655DF\logo.ico, In Quarantane, [62c9049e1b60d46295ef584c1ae846ba], 
PUP.Optional.OpenCandy, C:\Users\*************\AppData\Roaming\OpenCandy\E336715DE3BD4BF69F369517C69655DF\PokkiICO.exe, In Quarantane, [62c9049e1b60d46295ef584c1ae846ba], 
PUP.Optional.OpenCandy, C:\Users\*************\AppData\Roaming\OpenCandy\E336715DE3BD4BF69F369517C69655DF\PokkiInstaller.exe, In Quarantane, [62c9049e1b60d46295ef584c1ae846ba], 
PUP.Optional.Trovi, C:\Users\*************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.defaultenginename", "Trovi search");), Ersetzt,[3bf0d3cf6615eb4be4ac23b73cc80cf4]
PUP.Optional.Trovi, C:\Users\*************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.search.selectedEngine", "Trovi search");), Ersetzt,[3deef5adc9b2bd79f1a06575d034af51]
PUP.Optional.Trovi.A, C:\Users\*************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.trovi.com/?gd=&ctid=CT3318399&octid=EB_ORIGINAL_CTID&ISID=M9D0C5C87-F3FB-4236-ADF7-7845DC4C8DB7&SearchSource=55&CUI=&UM=5&UP=SP622ED464-78BE-4420-8EB7-DEEF1ABE0F62&SSPV=");), Ersetzt,[c764c8da3744989e58cee5f6ac5856aa]

Physische Sektoren: 0
(No malicious items detected)


(end)
         
AdwCleaner ist nach dem "Löschen" abgestürzt. Beim zweiten mal hat dann alles funktioniert. Deshalb zwei Logfiles:

Code:
ATTFilter
# AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 20:33:00
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : ********** - J-PC
# Gestartet von : C:\Users\**********\Desktop\adwcleaner_3.216.exe
# Option : Loschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****

Ordner Geloscht : C:\ProgramData\NCH Software
Ordner Geloscht : C:\Program Files (x86)\Conduit
Ordner Geloscht : C:\Program Files (x86)\NCH Software
Ordner Geloscht : C:\Windows\assembly\GAC_MSIL\QuickStoresToolbar
Ordner Geloscht : C:\Users\**********\AppData\Local\Mail.Ru
Ordner Geloscht : C:\Users\**********\AppData\LocalLow\Conduit
Ordner Geloscht : C:\Users\**********\AppData\Roaming\NCH Software
Ordner Geloscht : C:\Users\**********\AppData\Roaming\OCS
Ordner Geloscht : C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mail.Ru
Ordner Geloscht : C:\Program Files (x86)\Mozilla Firefox\Extensions\quickstores@quickstores.de
Ordner Geloscht : C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfglldanmpdjibmppnggdphndfklefg
Datei Geloscht : C:\Windows\System32\Uninstall.exe
Datei Geloscht : C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\QuickStores.url
Datei Geloscht : C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\foxydeal.sqlite
Datei Geloscht : C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\11-suche.xml
Datei Geloscht : C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\user.js

***** [ Verknupfungen ] *****


***** [ Registrierungsdatenbank ] *****

Schlussel Geloscht : HKCU\Software\Google\Chrome\Extensions\gdfglldanmpdjibmppnggdphndfklefg
Schlussel Geloscht : HKLM\SOFTWARE\Google\Chrome\Extensions\gdfglldanmpdjibmppnggdphndfklefg
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_ikea-home-planer_RASAPI32
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_ikea-home-planer_RASMANCS
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mkv-player_RASAPI32
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_mkv-player_RASMANCS
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_sweet-home-3d_RASAPI32
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_sweet-home-3d_RASMANCS
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlussel Geloscht : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlussel Geloscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlussel Geloscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlussel Geloscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Wert Geloscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{10EDB994-47F8-43F7-AE96-F2EA63E9F90F}]
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlussel Geloscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Schlussel Geloscht : HKCU\Software\OCS
Schlussel Geloscht : HKCU\Software\Softonic
Schlussel Geloscht : HKCU\Software\AppDataLow\Software\Conduit
Schlussel Geloscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlussel Geloscht : HKLM\Software\systweak
Schlussel Geloscht : HKLM\Software\Vittalia

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17207


-\\ Mozilla Firefox v26.0 (en-US)

[ Datei : C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\prefs.js ]

Zeile geloscht : user_pref("extensions.wrc.SearchRules.ask.com.url", "^hxxp(s)?\\\\:\\\\/\\\\/(.+\\\\.)?ask\\\\.com\\\\/.*");

-\\ Google Chrome v36.0.1985.125

[ Datei : C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Geloscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&CUI=UN12578523971378626&ctid=CT3305104&UM=2
Geloscht [Search Provider] : hxxp://www.softonic.de/s/{searchTerms}
Geloscht [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
Geloscht [Extension] : gdfglldanmpdjibmppnggdphndfklefg

*************************

AdwCleaner[R0].txt - [5313 octets] - [21/07/2014 20:29:27]
AdwCleaner[S0].txt - [5125 octets] - [21/07/2014 20:33:00]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5185 octets] ##########
         
Code:
ATTFilter
# AdwCleaner v3.216 - Bericht erstellt am 21/07/2014 um 20:36:43
# Aktualisiert 17/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : ************ - J-PC
# Gestartet von : C:\Users\************\Desktop\adwcleaner_3.216.exe
# Option : Loschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknupfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17207


-\\ Mozilla Firefox v26.0 (en-US)

[ Datei : C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\prefs.js ]


-\\ Google Chrome v36.0.1985.125

[ Datei : C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [5313 octets] - [21/07/2014 20:29:27]
AdwCleaner[R1].txt - [1087 octets] - [21/07/2014 20:36:18]
AdwCleaner[S0].txt - [5277 octets] - [21/07/2014 20:33:00]
AdwCleaner[S1].txt - [1009 octets] - [21/07/2014 20:36:43]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1069 octets] ##########
         
JRT.txt:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by ************ on 21.07.2014 at 20:41:03,97
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\************\AppData\Roaming\getrighttogo"
Successfully deleted: [Folder] "C:\Windows\syswow64\ai_recyclebin"



~~~ FireFox

Emptied folder: C:\Users\************\AppData\Roaming\mozilla\firefox\profiles\v7f3edsp.default\minidumps [45 files]



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Policies\Google [Blacklisted Policy]



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.07.2014 at 20:45:39,36
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
FRST.txt:

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-07-2014
Ran by ************ (administrator) on J-PC on 21-07-2014 21:22:57
Running from F:\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(DTS) C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Conceiva Pty. Ltd.) C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Valve Corporation) E:\Games\Steam\Steam.exe
(Banamalon) C:\Program Files (x86)\Banamalon\Windows Remote Service\WindowsRemoteService.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\************\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(DSDCS) C:\Program Files (x86)\DSDCS\DS4Tool\DS4Tool.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMon.exe
(Dropbox, Inc.) C:\Users\************\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonTaskbar.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\RazerCore.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonUiAcc.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [613536 2010-10-27] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379040 2010-10-27] (Atheros Commnucations)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2350880 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart 
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-07-06] (AVAST Software)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585560 2014-06-23] (Razer Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [Steam] => E:\Games\Steam\steam.exe [1753280 2014-07-16] (Valve Corporation)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [Windows Remote Service] => C:\Program Files (x86)\Banamalon\Windows Remote Service\WindowsRemoteService.exe [172544 2013-04-18] (Banamalon)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [24477056 2014-06-27] (Google)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe [3128352 2013-06-25] (Disc Soft Ltd)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [SkyDrive] => C:\Users\************\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [251048 2014-06-20] (Microsoft Corporation)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [DS4Tool] => C:\Program Files (x86)\DSDCS\DS4Tool\DS4Tool.exe [3021312 2014-07-19] (DSDCS)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{9069EE0A-7615-4D86-AD80-CA263E936DA6}\IcoUltraMon.ico ()
Startup: C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\************\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor.lnk
ShortcutTarget: Monitor.lnk -> C:\Users\************\AppData\Roaming\Realtime Soft\UltraMon\3.2.2\Profiles\Monitor.umprofile ()
Startup: C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2BD68E52572DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com?fr=hp-avast&type=prc265
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @mail.ru/GameCenter - C:\Users\************\AppData\Local\Mail.Ru\GameCenter\NPDetector.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\************\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - e:\Games\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\yahoo-avast.xml
FF Extension: Battlefield Heroes Updater - C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\battlefieldheroespatcher@ea.com [2012-04-14]
FF Extension: Battlefield Play4Free - C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\battlefieldplay4free@ea.com [2012-01-12]
FF Extension: ProxTube - Unblock YouTube - C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\ich@maltegoetz.de [2013-12-30]
FF Extension: YouTube Unblocker - C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\youtubeunblocker@unblocker.yt [2013-11-01]
FF Extension: WEB.DE MailCheck - C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\toolbar@web.de.xpi [2011-12-20]
FF Extension: Adblock Plus - C:\Users\************\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-01-06]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-09-15]

Chrome: 
=======
CHR HomePage: 
CHR Extension: (Google Docs) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-19]
CHR Extension: (Google Drive) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-06]
CHR Extension: (YouTube) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-19]
CHR Extension: (Google-Suche) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-19]
CHR Extension: (Google Wallet) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf [2013-12-25]
CHR Extension: (Google Mail) - C:\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-19]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\********\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-06-27]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-06]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2013-12-25]

==================== Services (Whitelisted) =================

R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [52896 2010-10-27] (Atheros Commnucations) [File not signed]
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-06] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-05-27] () [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [632352 2013-06-25] (Disc Soft Ltd)
R2 DTSAudioService; C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe [210024 2011-05-31] (DTS)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2014-02-28] (Futuremark)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
R2 Mezzmo; C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe [4386600 2013-10-03] (Conceiva Pty. Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S2 CsrBtOBEX-Dienst; "C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe" [X]

==================== Drivers (Whitelisted) ====================

S3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-06-04] ()
S1 ASMTFilter; C:\Windows\System32\DRIVERS\asmtufdriver.sys [21400 2014-03-03] (hxxp://www.asmedia.com.tw) [File not signed]
S1 ASMTFilter; C:\Windows\SysWOW64\DRIVERS\asmtufdriver.sys [21400 2013-01-28] (hxxp://www.asmedia.com.tw) [File not signed]
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2012-09-14] ()
S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-06] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-06] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-06] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-06] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-05-25] ()
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Limited)
R3 dtscsibus; C:\Windows\System32\DRIVERS\dtscsibus.sys [29696 2013-09-15] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-31] (Intel Corporation)
S3 libusb0; C:\Windows\System32\drivers\libusb0.sys [43456 2010-10-02] (hxxp://libusb-win32.sourceforge.net)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-05-25] ()
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13480 2014-06-10] ()
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39080 2014-05-19] (Razer Inc)
R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.)
R3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [34984 2014-05-19] (Razer Inc)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [530488 2011-12-17] (Duplex Secure Ltd.)
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project)
S3 vjoy; C:\Windows\System32\DRIVERS\vjoy.sys [45168 2014-03-06] (Shaul Eizikovich)
S3 xb1usb; C:\Windows\System32\DRIVERS\xb1usb.sys [34016 2014-05-27] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CsrBtPort; system32\DRIVERS\CsrBtPort.sys [X]
S3 csrhidmini; system32\DRIVERS\csrhidmini.sys [X]
S3 csrpan; system32\DRIVERS\csrpan.sys [X]
S3 csrserial; system32\DRIVERS\csrserial.sys [X]
S3 csrusb; System32\Drivers\csrusb.sys [X]
S3 e1cexpress; system32\DRIVERS\e1c62x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-21 20:45 - 2014-07-21 21:20 - 00001182 _____ () C:\Users\************\Desktop\JRT.txt
2014-07-21 20:41 - 2014-07-21 20:41 - 00000000 ____D () C:\Windows\ERUNT
2014-07-21 20:39 - 2014-07-21 20:36 - 00001149 _____ () C:\Users\************\Desktop\AdwCleaner[S1].txt
2014-07-21 20:39 - 2014-07-21 20:33 - 00005277 _____ () C:\Users\************\Desktop\AdwCleaner[S0].txt
2014-07-21 20:37 - 2014-07-21 20:37 - 00000000 ___RD () C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-21 20:29 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-21 20:28 - 2014-07-21 20:36 - 00000000 ____D () C:\AdwCleaner
2014-07-21 20:25 - 2014-07-21 20:24 - 01354223 _____ () C:\Users\************\Desktop\adwcleaner_3.216.exe
2014-07-21 20:22 - 2014-07-21 20:24 - 00003991 _____ () C:\Users\************\Desktop\mbam.txt
2014-07-21 20:11 - 2014-07-21 20:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 20:11 - 2014-07-21 20:11 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 20:11 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-21 20:11 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-21 20:11 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-21 13:59 - 2014-07-21 13:59 - 00049185 _____ () C:\ComboFix.txt
2014-07-21 13:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-21 13:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-21 13:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-21 13:23 - 2014-07-21 14:00 - 00000000 ____D () C:\Qoobox
2014-07-21 13:22 - 2014-07-21 20:18 - 00000000 ____D () C:\Windows\erdnt
2014-07-21 13:22 - 2014-07-21 13:21 - 05561612 ____R (Swearware) C:\Users\************\Desktop\ComboFix.exe
2014-07-20 22:32 - 2014-07-19 00:17 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\************\Desktop\tdsskiller.exe
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS4Tool
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\Program Files (x86)\DSDCS
2014-07-19 23:38 - 2014-07-19 23:38 - 00001228 _____ () C:\Users\************\Desktop\Revo Uninstaller.lnk
2014-07-19 23:38 - 2014-07-19 23:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-19 12:53 - 2014-07-19 02:41 - 00040610 _____ () C:\Users\************\Desktop\Logfiles.rar
2014-07-19 02:32 - 2014-07-19 02:39 - 00000000 ____D () C:\Users\************\Desktop\Neuer Ordner (3)
2014-07-19 01:26 - 2014-07-21 21:22 - 00000000 ____D () C:\FRST
2014-07-19 01:21 - 2014-07-19 01:21 - 00000000 ____D () C:\found.005
2014-07-19 01:17 - 2014-07-19 01:17 - 00000020 _____ () C:\Users\************\defogger_reenable
2014-07-18 23:14 - 2014-07-18 23:14 - 00007200 ____N () C:\bootsqm.dat
2014-07-18 23:14 - 2014-07-18 23:14 - 00000000 ____D () C:\found.004
2014-07-17 14:13 - 2014-07-17 14:13 - 00000967 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2014-07-17 14:09 - 2014-07-17 14:09 - 00301200 _____ () C:\Windows\Minidump\071714-10779-01.dmp
2014-07-17 14:08 - 2014-07-17 14:08 - 00000000 ____D () C:\found.003
2014-07-16 19:48 - 2014-07-16 19:48 - 00009568 _____ () C:\Users\************\Desktop\002.txt
2014-07-16 19:47 - 2014-07-16 19:47 - 00001828 _____ () C:\Users\************\Desktop\001.txt
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Program Files (x86)\NirSoft
2014-07-16 17:06 - 2014-07-16 17:06 - 00293456 _____ () C:\Windows\Minidump\071614-14133-01.dmp
2014-07-16 17:05 - 2014-07-16 17:05 - 00000000 ____D () C:\found.002
2014-07-16 16:52 - 2014-07-16 16:52 - 00262144 _____ () C:\Windows\Minidump\071614-11076-01.dmp
2014-07-16 16:51 - 2014-07-16 16:51 - 00000000 ____D () C:\found.001
2014-07-10 15:29 - 2014-07-19 13:26 - 00000000 ____D () C:\Users\************\AppData\Local\Arma 3
2014-07-10 15:29 - 2014-07-17 15:25 - 00000000 ____D () C:\Users\************\Eigene Dokumente\Arma 3
2014-07-10 15:29 - 2014-07-10 15:29 - 00000000 ____D () C:\ProgramData\Bohemia Interactive
2014-07-09 12:19 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 12:19 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 12:19 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 12:19 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 12:19 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 12:19 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 12:19 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 12:19 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 12:18 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 12:18 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 12:18 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 12:18 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 12:18 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 12:18 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 12:18 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 12:18 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 12:18 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 12:18 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 12:18 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 12:18 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 12:18 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 12:18 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 12:18 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 12:18 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 12:18 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 12:18 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 12:18 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 12:18 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 12:18 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 12:18 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 12:18 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 12:18 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 12:18 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 12:18 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 12:18 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 12:18 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 12:18 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 12:18 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 12:18 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 12:18 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 12:18 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 12:18 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 12:18 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 12:18 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 12:18 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 12:18 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 12:18 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 12:18 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 12:18 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 12:18 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 12:18 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 12:18 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 12:18 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 12:18 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 12:18 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 12:18 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 12:18 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 12:18 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 12:18 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 12:18 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 12:18 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 12:18 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 12:18 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 12:18 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 12:18 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 12:18 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 12:18 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-09 12:13 - 2012-03-12 19:26 - 00001386 _____ () C:\Users\************\Desktop\Skype.lnk
2014-07-07 09:08 - 2014-07-07 09:08 - 00003246 _____ () C:\Windows\System32\Tasks\SamsungMagician
2014-07-07 09:08 - 2014-07-07 09:08 - 00001067 _____ () C:\Users\Public\Desktop\Samsung Magician.lnk
2014-07-07 09:08 - 2014-07-07 09:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2014-07-06 23:52 - 2014-04-18 17:02 - 00129472 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzDxgk.sys
2014-07-06 23:52 - 2014-04-18 17:02 - 00074432 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzFilter.sys
2014-07-06 23:34 - 2014-07-17 20:42 - 00001926 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-06 23:34 - 2014-07-06 23:34 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-06 23:29 - 2014-07-06 23:26 - 00237764 _____ () C:\Users\************\Desktop\WER-21122-0.sysdata.xml
2014-07-06 23:28 - 2014-07-06 23:28 - 00001014 _____ () C:\Users\************\Desktop\Minidump - Verknüpfung.lnk
2014-07-06 23:26 - 2014-07-06 23:26 - 00301232 _____ () C:\Windows\Minidump\070614-10452-01.dmp
2014-07-06 23:18 - 2014-07-06 23:18 - 00000000 ____D () C:\found.000
2014-07-01 23:45 - 2014-07-02 00:00 - 00000000 ____D () C:\Users\************\AppData\Roaming\SpinTires
2014-07-01 23:44 - 2014-07-01 23:44 - 00000650 _____ () C:\Users\************\Desktop\Spintires.lnk
2014-07-01 23:44 - 2014-07-01 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spintires
2014-06-28 02:21 - 2014-06-28 02:21 - 00000000 ____D () C:\Users\************\AppData\Local\Sniper3
2014-06-25 20:30 - 2014-06-25 20:30 - 00000000 ____D () C:\Program Files\Microsoft Xbox One Controller for Windows
2014-06-24 03:09 - 2014-06-24 03:09 - 00000000 ____D () C:\Users\************\AppData\Local\Oblivion
2014-06-24 03:06 - 2014-06-24 03:06 - 00001328 _____ () C:\Users\************\Desktop\The Elder Scrolls Morrowind Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001311 _____ () C:\Users\************\Desktop\The Elder Scrolls Oblivion Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001294 _____ () C:\Users\************\Desktop\The Elder Scrolls Skyrim Legendary Edition Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001283 _____ () C:\Users\************\Desktop\The Elder Scrolls Morrowind Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001271 _____ () C:\Users\************\Desktop\The Elder Scrolls Oblivion Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001240 _____ () C:\Users\************\Desktop\The Elder Scrolls Skyrim Legendary Edition.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001232 _____ () C:\Users\************\Desktop\The Elder Scrolls Daggerfall.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001193 _____ () C:\Users\************\Desktop\The Elder Scrolls Arena.lnk
2014-06-24 02:31 - 2014-06-24 02:31 - 00000000 __SHD () C:\ProgramData\SecuROM

==================== One Month Modified Files and Folders =======

2014-07-21 21:22 - 2014-07-19 01:26 - 00000000 ____D () C:\FRST
2014-07-21 21:20 - 2014-07-21 20:45 - 00001182 _____ () C:\Users\************\Desktop\JRT.txt
2014-07-21 20:56 - 2012-10-04 18:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-21 20:44 - 2009-07-14 06:45 - 00032688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-21 20:44 - 2009-07-14 06:45 - 00032688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-21 20:43 - 2010-11-21 08:50 - 00699594 _____ () C:\Windows\system32\perfh007.dat
2014-07-21 20:43 - 2010-11-21 08:50 - 00153862 _____ () C:\Windows\system32\perfc007.dat
2014-07-21 20:43 - 2009-07-14 07:13 - 01649420 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-21 20:41 - 2014-07-21 20:41 - 00000000 ____D () C:\Windows\ERUNT
2014-07-21 20:38 - 2013-01-14 16:37 - 00000000 ____D () C:\Users\************\AppData\Roaming\Dropbox
2014-07-21 20:38 - 2011-12-17 02:03 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-21 20:37 - 2014-07-21 20:37 - 00000000 ___RD () C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-21 20:37 - 2014-05-15 18:20 - 00000000 ____D () C:\Users\************\AppData\Roaming\DropboxMaster
2014-07-21 20:37 - 2014-03-14 15:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-21 20:37 - 2014-03-06 08:57 - 00167240 _____ () C:\Windows\PFRO.log
2014-07-21 20:37 - 2014-03-06 08:57 - 00093888 _____ () C:\Windows\setupact.log
2014-07-21 20:37 - 2013-07-20 14:35 - 00000043 _____ () C:\Windows\MezzmoMediaServer.INI
2014-07-21 20:37 - 2011-12-16 20:04 - 01424933 _____ () C:\Windows\WindowsUpdate.log
2014-07-21 20:37 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-21 20:36 - 2014-07-21 20:39 - 00001149 _____ () C:\Users\************\Desktop\AdwCleaner[S1].txt
2014-07-21 20:36 - 2014-07-21 20:28 - 00000000 ____D () C:\AdwCleaner
2014-07-21 20:35 - 2011-12-17 15:14 - 00000000 ____D () C:\Users\************\AppData\Local\CrashDumps
2014-07-21 20:33 - 2014-07-21 20:39 - 00005277 _____ () C:\Users\************\Desktop\AdwCleaner[S0].txt
2014-07-21 20:29 - 2011-12-17 02:03 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-21 20:24 - 2014-07-21 20:25 - 01354223 _____ () C:\Users\************\Desktop\adwcleaner_3.216.exe
2014-07-21 20:24 - 2014-07-21 20:22 - 00003991 _____ () C:\Users\************\Desktop\mbam.txt
2014-07-21 20:21 - 2014-07-21 20:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 20:18 - 2014-07-21 13:22 - 00000000 ____D () C:\Windows\erdnt
2014-07-21 20:11 - 2014-07-21 20:11 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 14:00 - 2014-07-21 13:23 - 00000000 ____D () C:\Qoobox
2014-07-21 13:59 - 2014-07-21 13:59 - 00049185 _____ () C:\ComboFix.txt
2014-07-21 13:52 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-21 13:51 - 2009-07-14 04:34 - 75497472 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 30932992 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 05242880 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-07-21 13:21 - 2014-07-21 13:22 - 05561612 ____R (Swearware) C:\Users\************\Desktop\ComboFix.exe
2014-07-21 00:48 - 2011-12-18 02:52 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{01D039A5-45B5-4A9C-AC86-320D09BCFF9A}
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS4Tool
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\Program Files (x86)\DSDCS
2014-07-20 22:25 - 2014-06-14 01:13 - 00000987 _____ () C:\Users\Public\Desktop\DS4Tool.lnk
2014-07-20 22:25 - 2014-06-14 01:12 - 00000000 ____D () C:\Users\************\AppData\Roaming\DSDCS
2014-07-20 01:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-19 23:38 - 2014-07-19 23:38 - 00001228 _____ () C:\Users\************\Desktop\Revo Uninstaller.lnk
2014-07-19 23:38 - 2014-07-19 23:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-19 13:26 - 2014-07-10 15:29 - 00000000 ____D () C:\Users\************\AppData\Local\Arma 3
2014-07-19 02:44 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-19 02:42 - 2011-12-23 21:19 - 00000000 ____D () C:\Windows\Minidump
2014-07-19 02:42 - 2011-12-16 20:00 - 00303938 ____N () C:\Windows\Minidump\071914-10389-01.dmp
2014-07-19 02:41 - 2014-07-19 12:53 - 00040610 _____ () C:\Users\************\Desktop\Logfiles.rar
2014-07-19 02:39 - 2014-07-19 02:32 - 00000000 ____D () C:\Users\************\Desktop\Neuer Ordner (3)
2014-07-19 01:21 - 2014-07-19 01:21 - 00000000 ____D () C:\found.005
2014-07-19 01:17 - 2014-07-19 01:17 - 00000020 _____ () C:\Users\************\defogger_reenable
2014-07-19 01:17 - 2011-12-16 20:04 - 00000000 ____D () C:\Users\************
2014-07-19 00:17 - 2014-07-20 22:32 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\************\Desktop\tdsskiller.exe
2014-07-18 23:40 - 2014-03-18 09:43 - 00000000 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2014-07-18 23:16 - 2014-04-04 08:33 - 00495484 _____ () C:\Windows\DPINST.LOG
2014-07-18 23:15 - 2011-12-16 20:00 - 00303910 ____N () C:\Windows\Minidump\071814-10561-01.dmp
2014-07-18 23:14 - 2014-07-18 23:14 - 00007200 ____N () C:\bootsqm.dat
2014-07-18 23:14 - 2014-07-18 23:14 - 00000000 ____D () C:\found.004
2014-07-18 12:05 - 2014-03-16 01:39 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-07-18 10:31 - 2013-09-15 22:37 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-07-17 20:42 - 2014-07-06 23:34 - 00001926 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-17 15:25 - 2014-07-10 15:29 - 00000000 ____D () C:\Users\************\Eigene Dokumente\Arma 3
2014-07-17 14:13 - 2014-07-17 14:13 - 00000967 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2014-07-17 14:13 - 2011-12-17 03:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2014-07-17 14:09 - 2014-07-17 14:09 - 00301200 _____ () C:\Windows\Minidump\071714-10779-01.dmp
2014-07-17 14:09 - 2014-03-14 15:23 - 666796358 _____ () C:\Windows\MEMORY.DMP
2014-07-17 14:08 - 2014-07-17 14:08 - 00000000 ____D () C:\found.003
2014-07-16 19:48 - 2014-07-16 19:48 - 00009568 _____ () C:\Users\************\Desktop\002.txt
2014-07-16 19:47 - 2014-07-16 19:47 - 00001828 _____ () C:\Users\************\Desktop\001.txt
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Program Files (x86)\NirSoft
2014-07-16 17:06 - 2014-07-16 17:06 - 00293456 _____ () C:\Windows\Minidump\071614-14133-01.dmp
2014-07-16 17:05 - 2014-07-16 17:05 - 00000000 ____D () C:\found.002
2014-07-16 16:52 - 2014-07-16 16:52 - 00262144 _____ () C:\Windows\Minidump\071614-11076-01.dmp
2014-07-16 16:51 - 2014-07-16 16:51 - 00000000 ____D () C:\found.001
2014-07-11 11:14 - 2014-03-16 01:39 - 00001050 _____ () C:\Users\************\Desktop\MSI Afterburner.lnk
2014-07-11 02:41 - 2011-12-20 06:10 - 00000000 ____D () C:\Users\************\AppData\Roaming\Skype
2014-07-10 15:29 - 2014-07-10 15:29 - 00000000 ____D () C:\ProgramData\Bohemia Interactive
2014-07-10 15:29 - 2014-03-20 11:32 - 00000000 ___RD () C:\Users\************\Eigene Dokumente
2014-07-10 15:29 - 2014-03-11 11:55 - 00153422 _____ () C:\Windows\DirectX.log
2014-07-09 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-09 19:23 - 2009-07-14 06:45 - 00335488 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 19:22 - 2014-05-07 00:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-09 19:22 - 2010-11-21 09:00 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 19:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-09 19:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 16:26 - 2013-08-15 12:47 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 16:26 - 2011-12-19 21:02 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 01:56 - 2012-10-04 18:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-09 01:56 - 2012-04-03 19:41 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 01:56 - 2011-12-17 04:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-08 12:29 - 2012-07-12 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-07-07 09:08 - 2014-07-07 09:08 - 00003246 _____ () C:\Windows\System32\Tasks\SamsungMagician
2014-07-07 09:08 - 2014-07-07 09:08 - 00001067 _____ () C:\Users\Public\Desktop\Samsung Magician.lnk
2014-07-07 09:08 - 2014-07-07 09:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2014-07-07 09:08 - 2014-03-02 05:04 - 00000000 ____D () C:\Program Files (x86)\Samsung Magician
2014-07-06 23:52 - 2013-10-26 14:09 - 00000000 ____D () C:\Windows\Razer Core
2014-07-06 23:52 - 2013-08-18 01:12 - 00000000 ____D () C:\ProgramData\Razer
2014-07-06 23:52 - 2012-01-27 19:26 - 00000000 ____D () C:\Program Files (x86)\Razer
2014-07-06 23:51 - 2011-12-16 20:10 - 00069432 _____ () C:\Users\************\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-06 23:50 - 2012-01-27 19:33 - 00000000 ____D () C:\Users\************\AppData\Local\Razer
2014-07-06 23:49 - 2012-01-27 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2014-07-06 23:34 - 2014-07-06 23:34 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-06 23:34 - 2014-04-19 20:37 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-06 23:34 - 2013-12-19 08:52 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-07-06 23:34 - 2011-12-17 02:03 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-07-06 23:28 - 2014-07-06 23:28 - 00001014 _____ () C:\Users\************\Desktop\Minidump - Verknüpfung.lnk
2014-07-06 23:26 - 2014-07-06 23:29 - 00237764 _____ () C:\Users\************\Desktop\WER-21122-0.sysdata.xml
2014-07-06 23:26 - 2014-07-06 23:26 - 00301232 _____ () C:\Windows\Minidump\070614-10452-01.dmp
2014-07-06 23:18 - 2014-07-06 23:18 - 00000000 ____D () C:\found.000
2014-07-02 00:00 - 2014-07-01 23:45 - 00000000 ____D () C:\Users\************\AppData\Roaming\SpinTires
2014-07-01 23:44 - 2014-07-01 23:44 - 00000650 _____ () C:\Users\************\Desktop\Spintires.lnk
2014-07-01 23:44 - 2014-07-01 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spintires
2014-06-30 08:45 - 2014-05-25 12:18 - 00000000 ____D () C:\Users\************\AppData\Roaming\DS4Tool
2014-06-30 04:09 - 2014-07-09 12:19 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-09 12:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-28 02:21 - 2014-06-28 02:21 - 00000000 ____D () C:\Users\************\AppData\Local\Sniper3
2014-06-25 20:56 - 2014-03-20 11:33 - 00000000 ____D () C:\Users\************\Eigene Dokumente\My Games
2014-06-25 20:56 - 2012-02-04 10:36 - 00000000 ____D () C:\ProgramData\Codemasters
2014-06-25 20:30 - 2014-06-25 20:30 - 00000000 ____D () C:\Program Files\Microsoft Xbox One Controller for Windows
2014-06-25 19:36 - 2013-09-19 00:52 - 00000216 _____ () C:\Users\************\d3d_antilag.log
2014-06-25 19:34 - 2014-03-20 11:33 - 00006583 _____ () C:\Users\************\Eigene Dokumente\TombRaider.log
2014-06-24 03:35 - 2012-01-18 13:58 - 00000000 ____D () C:\Users\************\AppData\Local\Origin
2014-06-24 03:35 - 2012-01-18 13:58 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-24 03:35 - 2011-12-17 23:00 - 00000000 ____D () C:\ProgramData\Origin
2014-06-24 03:09 - 2014-06-24 03:09 - 00000000 ____D () C:\Users\************\AppData\Local\Oblivion
2014-06-24 03:09 - 2012-02-02 01:24 - 00000000 ____D () C:\Users\************\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-06-24 03:06 - 2014-06-24 03:06 - 00001328 _____ () C:\Users\************\Desktop\The Elder Scrolls Morrowind Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001311 _____ () C:\Users\************\Desktop\The Elder Scrolls Oblivion Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001294 _____ () C:\Users\************\Desktop\The Elder Scrolls Skyrim Legendary Edition Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001283 _____ () C:\Users\************\Desktop\The Elder Scrolls Morrowind Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001271 _____ () C:\Users\************\Desktop\The Elder Scrolls Oblivion Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001240 _____ () C:\Users\************\Desktop\The Elder Scrolls Skyrim Legendary Edition.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001232 _____ () C:\Users\************\Desktop\The Elder Scrolls Daggerfall.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001193 _____ () C:\Users\************\Desktop\The Elder Scrolls Arena.lnk
2014-06-24 02:31 - 2014-06-24 02:31 - 00000000 __SHD () C:\ProgramData\SecuROM
2014-06-23 21:39 - 2014-03-20 11:33 - 00000000 ____D () C:\Users\************\Eigene Dokumente\ArcheAge
2014-06-23 21:35 - 2014-04-02 16:34 - 00000000 ____D () C:\ArcheAge
2014-06-23 21:32 - 2014-04-11 15:09 - 00000000 ____D () C:\Program Files (x86)\Glyph
2014-06-22 22:38 - 2013-03-11 22:36 - 00000000 ____D () C:\Users\************\AppData\Roaming\vlc
2014-06-21 12:24 - 2011-12-17 02:03 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-21 12:24 - 2011-12-17 02:03 - 00003868 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore

Some content of TEMP:
====================
C:\Users\************\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpvb1dhj.dll
C:\Users\************\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-19 23:37

==================== End Of Log ============================
         
--- --- ---

--- --- ---

--- --- ---

Alt 22.07.2014, 11:08   #20
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 22.07.2014, 20:50   #21
pilimen400
 
Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Abstürze habe ich keine mehr. Der Avast Schutz lässt sich immer noch nicht aktivieren.

ESET Online Scanner:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7623
# api_version=3.0.2
# EOSSerial=5a26afbef8ec5b49b1b8c428c5a834af
# engine=19292
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-07-22 04:08:14
# local_time=2014-07-22 06:08:14 (+0100, Mitteleuropдische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='avast! Antivirus'
# compatibility_mode=783 16777214 100 97 422771 170465784 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 15322 157675144 0 0
# scanned=410597
# found=26
# cleaned=0
# scan_time=8765
sh=FB2BCD5A889DB9658B02E8ED3A95043BAA0094E1 ft=1 fh=f6a034ccf475a4f7 vn="Win32/Toolbar.Conduit.AC evtl. unerwunschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Conduit\CT3305104\plugins\TBVerifier.dll.vir"
sh=2B9A1340BEC2FE2694C333ACD77F0E12EF9550D1 ft=1 fh=fcbeb3ad261a92d1 vn="Variante von Win32/Conduit.SearchProtect.P evtl. unerwunschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfglldanmpdjibmppnggdphndfklefg\10.31.4.510_0\APISupport\APISupport.dll.vir"
sh=675526C1B3CB27C6635233B62EDB8ECEEBFE1556 ft=1 fh=8382eeac10eb278f vn="Variante von Win32/Toolbar.Conduit.AH evtl. unerwunschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfglldanmpdjibmppnggdphndfklefg\10.31.4.510_0\nativeMessaging\TBMessagingHost.exe.vir"
sh=C0114483C9E2C1271B0D594AB6A6BF1E4F383D63 ft=1 fh=e2607344a0894545 vn="Variante von Win32/Conduit.SearchProtect.N evtl. unerwunschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\************\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfglldanmpdjibmppnggdphndfklefg\10.31.4.510_0\plugins\ChromeApiPlugin.dll.vir"
sh=AD5CC754438CD330049A78876A426DEFD8DC21E6 ft=0 fh=0000000000000000 vn="Variante von Win32/Toolbar.Conduit.AH evtl. unerwunschte Anwendung" ac=I fn="C:\Users\************\AppData\Local\CRE\gdfglldanmpdjibmppnggdphndfklefg.crx"
sh=B1413B57C42D7DE916F69234DB1307E5AE5BEEAF ft=0 fh=0000000000000000 vn="Mehrere Bedrohungen" ac=I fn="C:\Users\************\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18\41fb7cd2-3d501bfa"
sh=724EB6A527AF3BB9C8E1F7DF76F8D25D0AC65C87 ft=1 fh=2d28668520f8d7e0 vn="Variante von Win32/HackTool.Crack.BL potenziell unsichere Anwendung" ac=I fn="E:\Games\Dark Souls 2\Game\steam_api.dll"
sh=8FCCC46311F67DD17FDBC0124C5ACB91E4FD8C55 ft=1 fh=f9c15dce14dd30ee vn="Variante von Win32/Packed.VMProtect.ABD Trojaner" ac=I fn="E:\Games\State of Decay\steam_api.dll"
sh=2BCF13A9D3761AF6896EDC1F81394F4A8B46783B ft=1 fh=56c5c514a7f4002c vn="Win32/DownWare.L evtl. unerwunschte Anwendung" ac=I fn="E:\Home\Datenbank\Tools\Brenn Programme\DAEMON Tools\DAEMONTools.exe"
sh=5B722EF9EF74E6BE09D107AD6EF877F8459E6F3B ft=0 fh=0000000000000000 vn="Variante von Win32/Keygen.AD potenziell unsichere Anwendung" ac=I fn="E:\Home\Datenbank\Tools\Systemtools\UltraMon_3.2.2.rar"
sh=7EFA518E74CC4DD03104F037D2B39FF0DDA87C96 ft=0 fh=0000000000000000 vn="Win32/RemoteAdmin.NetCat potenziell unsichere Anwendung" ac=I fn="E:\Home\Datenbank\Tools\Tauschborsen\CryptLoad_1.0.5.rar"
sh=AC30EEBA04B8BAC596EC77945C3BD25BCA0F0F56 ft=1 fh=22d109dcb5415bf3 vn="Win32/Toolbar.Widgi evtl. unerwunschte Anwendung" ac=I fn="E:\Home\Datenbank\Treiber, Updates\Codecs\media.player.codec.pack.v3.9.6.setup.exe"
sh=7D68A5ADF68C83A44A3718C67B210449AF8ED03C ft=1 fh=0592301bd08d1582 vn="Variante von Win32/HackTool.CheatEngine.AB potenziell unsichere Anwendung" ac=I fn="E:\Home\Game Tools\Mount & Blade\Warband\Trainer 1.113\Mount & Blade Warband Trainer +10 v1.113.exe"
sh=A0BCF03A49845AD4A1049D3C4B08E7442F3CDFB7 ft=0 fh=0000000000000000 vn="Win32/PrcView potenziell unsichere Anwendung" ac=I fn="F:\BRENNEN\Spiele\SYSTEMSHOCK-Portable-v1.2.7z"
sh=4122CF816AAA01E63CFB76CD151F2851BC055481 ft=1 fh=447f47bd8295ab0e vn="Win32/RemoteAdmin.NetCat potenziell unsichere Anwendung" ac=I fn="F:\CryptLoad\router\FRITZ!Box\nc.exe"
sh=4122CF816AAA01E63CFB76CD151F2851BC055481 ft=1 fh=447f47bd8295ab0e vn="Win32/RemoteAdmin.NetCat potenziell unsichere Anwendung" ac=I fn="F:\CryptLoad\tools\router\FRITZ!Box\nc.exe"
sh=57C14A5E853051DE4CFDFFB659A363B0D2FEDA27 ft=1 fh=bd67c738db7f20da vn="Variante von Win32/Toolbar.Widdit.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\1Player.exe"
sh=2A84624EC8B9560693AE6A8207FDF0429264E25B ft=1 fh=d235e65c79dc576e vn="Variante von Win32/DownloadSponsor.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\BlueScreenView - CHIP-Installer.exe"
sh=E788647FC140752367322469D3FF047FC7CC39A4 ft=1 fh=90ed368ea13e7de0 vn="Variante von Win32/Amonetize.BI evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Setup__4006_il174.exe"
sh=1B1BC8F97B54B9A21DD802BAF10AAFF9CB4C955C ft=1 fh=bf31d3ea3574fbbc vn="Variante von Win32/DownloadSponsor.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Microsoft OneDrive SkyDrive - CHIP-Installer.exe"
sh=F490262E0C104D4959CF698FDEAC5A522E933B1F ft=1 fh=6ba1933148abe144 vn="Variante von Win32/DownloadSponsor.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Microsoft SyncToy 64 Bit - CHIP-Installer.exe"
sh=6700B40EB568B4E8B4B0FD6A853A02ADFBA1C9DC ft=1 fh=d35c2cd127d25f94 vn="Variante von Win32/Verti.F evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Nicht bestatigt 934536.crdownload"
sh=437E072172444563E8377AFD19B0E3113A88B107 ft=1 fh=6e6afe82ff92f866 vn="Variante von Win32/DownloadSponsor.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Nvidia GeForce Experience - CHIP-Installer.exe"
sh=79282CD2E3D7DE546CCA1FDDF987E340CA47D506 ft=1 fh=103fb1e48fb55d09 vn="Variante von Win32/DownloadSponsor.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Slender The Eight Pages - CHIP-Downloader.exe"
sh=8424C31692CD2F0F46E4479A882C2290AA6CC230 ft=1 fh=2feb8829d269cebc vn="Win32/SoftonicDownloader.G evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\SoftonicDownloader_fuer_debut-video-capture-software.exe"
sh=6A5B8FA6CBF2CCA25855E6B82071C643CA024726 ft=1 fh=97757c6675b4964e vn="Variante von Win32/DownloadSponsor.A evtl. unerwunschte Anwendung" ac=I fn="F:\Downloads\Xilisoft MKV Converter - CHIP-Installer.exe"
         
checkup.txt:
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.85  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Spybot - Search & Destroy 
 JavaFX 2.1.1    
 Java 7 Update 17  
 Java 7 Update 21  
 Java 7 Update 51  
 Java version out of Date! 
 Adobe Flash Player 14.0.0.145  
 Adobe Reader 10.1.10 Adobe Reader out of Date!  
 Mozilla Firefox (26.0) 
 Google Chrome 35.0.1916.153  
 Google Chrome 36.0.1985.125  
````````Process Check: objlist.exe by Laurent````````  
 Spybot Teatimer.exe is disabled! 
 Banamalon Windows Remote Service WindowsRemoteService.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST.txt:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-07-2014
Ran by ********** (administrator) on J-PC on 22-07-2014 21:40:29
Running from F:\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(DTS) C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Conceiva Pty. Ltd.) C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\64bit\RzOvlMon.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Valve Corporation) E:\Games\Steam\Steam.exe
(Banamalon) C:\Program Files (x86)\Banamalon\Windows Remote Service\WindowsRemoteService.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Users\**********\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
(DSDCS) C:\Program Files (x86)\DSDCS\DS4Tool\DS4Tool.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMon.exe
(Dropbox, Inc.) C:\Users\**********\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung Magician\Samsung Magician.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonTaskbar.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\Core\RazerCore.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonUiAcc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [613536 2010-10-27] (Atheros Communications)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379040 2010-10-27] (Atheros Commnucations)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-19] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2350880 2014-05-30] (NVIDIA Corporation)
HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart 
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-07-06] (AVAST Software)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585560 2014-06-23] (Razer Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [Steam] => E:\Games\Steam\steam.exe [1753280 2014-07-16] (Valve Corporation)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [Windows Remote Service] => C:\Program Files (x86)\Banamalon\Windows Remote Service\WindowsRemoteService.exe [172544 2013-04-18] (Banamalon)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [24477056 2014-06-27] (Google)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe [3128352 2013-06-25] (Disc Soft Ltd)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [SkyDrive] => C:\Users\**********\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [251048 2014-06-20] (Microsoft Corporation)
HKU\S-1-5-21-2237465050-2375263089-2847873979-1000\...\Run: [DS4Tool] => C:\Program Files (x86)\DSDCS\DS4Tool\DS4Tool.exe [3021312 2014-07-19] (DSDCS)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{9069EE0A-7615-4D86-AD80-CA263E936DA6}\IcoUltraMon.ico ()
Startup: C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\**********\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor.lnk
ShortcutTarget: Monitor.lnk -> C:\Users\**********\AppData\Roaming\Realtime Soft\UltraMon\3.2.2\Profiles\Monitor.umprofile ()
Startup: C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Windows\System32\schtasks.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers-x32:  SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32:  SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x2BD68E52572DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://de.yahoo.com?fr=hp-avast&type=prc265
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKCU - {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default
FF SearchEngineOrder.1: Yahoo! (Avast)
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @esn/esnlaunch,version=1.110.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.110.0\npesnlaunch.dll No File
FF Plugin-x32: @esn/esnlaunch,version=1.122.0 - C:\Program Files (x86)\Battlelog Web Plugins\1.122.0\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @esn/esnlaunch,version=2.1.2 - C:\Program Files (x86)\Battlelog Web Plugins\2.1.2\npesnlaunch.dll (ESN Social Software AB)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 - C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll (Logitech Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @mail.ru/GameCenter - C:\Users\**********\AppData\Local\Mail.Ru\GameCenter\NPDetector.dll No File
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\**********\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - e:\Games\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\searchplugins\yahoo-avast.xml
FF Extension: Battlefield Heroes Updater - C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\battlefieldheroespatcher@ea.com [2012-04-14]
FF Extension: Battlefield Play4Free - C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\battlefieldplay4free@ea.com [2012-01-12]
FF Extension: ProxTube - Unblock YouTube - C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\ich@maltegoetz.de [2013-12-30]
FF Extension: YouTube Unblocker - C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\youtubeunblocker@unblocker.yt [2013-11-01]
FF Extension: WEB.DE MailCheck - C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\toolbar@web.de.xpi [2011-12-20]
FF Extension: Adblock Plus - C:\Users\**********\AppData\Roaming\Mozilla\Firefox\Profiles\v7f3edsp.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-01-06]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-04-11]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-09-15]

Chrome: 
=======
CHR HomePage: 
CHR Extension: (Google Docs) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-19]
CHR Extension: (Google Drive) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-06]
CHR Extension: (YouTube) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-19]
CHR Extension: (Google-Suche) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-19]
CHR Extension: (Google Wallet) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22]
CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf [2013-12-25]
CHR Extension: (Google Mail) - C:\Users\**********\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-19]
CHR HKCU\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\**********\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2013-06-27]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-06]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-04-11]
CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2013-12-25]

==================== Services (Whitelisted) =================

R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [52896 2010-10-27] (Atheros Commnucations) [File not signed]
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-06] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-05-27] () [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390720 2014-04-11] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1764992 2014-04-11] (Microsoft Corporation)
R3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [632352 2013-06-25] (Disc Soft Ltd)
R2 DTSAudioService; C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe [210024 2011-05-31] (DTS)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240584 2012-10-02] (DTS, Inc)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [520416 2014-02-28] (Futuremark)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation)
R2 Mezzmo; C:\Program Files (x86)\Conceiva\Mezzmo\MezzmoMediaServer.exe [4386600 2013-10-03] (Conceiva Pty. Ltd.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation)
R2 RzOvlMon; C:\Program Files (x86)\Razer\Core\64bit\rzovlmon.exe [32960 2014-04-18] (Razer, Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
S2 CsrBtOBEX-Dienst; "C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe" [X]

==================== Drivers (Whitelisted) ====================

S3 AiChargerPlus; C:\Windows\SysWow64\drivers\AiChargerPlus.sys [14848 2013-01-28] (ASUSTek Computer Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-06-04] ()
S1 ASMTFilter; C:\Windows\System32\DRIVERS\asmtufdriver.sys [21400 2014-03-03] (hxxp://www.asmedia.com.tw) [File not signed]
S1 ASMTFilter; C:\Windows\SysWOW64\DRIVERS\asmtufdriver.sys [21400 2013-01-28] (hxxp://www.asmedia.com.tw) [File not signed]
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2012-09-14] ()
S3 ASUSFILTER; C:\Windows\SysWow64\drivers\ASUSFILTER.sys [46152 2011-09-20] (MCCI Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-06] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-06] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-06] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-06] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-06] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-06] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-06] ()
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-05-25] ()
S3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Limited)
R3 dtscsibus; C:\Windows\System32\DRIVERS\dtscsibus.sys [29696 2013-09-15] (Disc Soft Ltd)
R3 e1dexpress; C:\Windows\System32\DRIVERS\e1d62x64.sys [495376 2013-05-31] (Intel Corporation)
S3 libusb0; C:\Windows\System32\drivers\libusb0.sys [43456 2010-10-02] (hxxp://libusb-win32.sourceforge.net)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-05-25] ()
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-03] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13480 2014-06-10] ()
R3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
R3 rzendpt; C:\Windows\System32\DRIVERS\rzendpt.sys [39080 2014-05-19] (Razer Inc)
R1 RzFilter; C:\Windows\system32\drivers\RzFilter.sys [74432 2014-04-18] (Razer, Inc.)
R3 rzmpos; C:\Windows\System32\DRIVERS\rzmpos.sys [34984 2014-05-19] (Razer Inc)
R3 ScpVBus; C:\Windows\System32\DRIVERS\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [530488 2011-12-17] (Duplex Secure Ltd.)
S3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project)
S3 vjoy; C:\Windows\System32\DRIVERS\vjoy.sys [45168 2014-03-06] (Shaul Eizikovich)
S3 xb1usb; C:\Windows\System32\DRIVERS\xb1usb.sys [34016 2014-05-27] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 CsrBtPort; system32\DRIVERS\CsrBtPort.sys [X]
S3 csrhidmini; system32\DRIVERS\csrhidmini.sys [X]
S3 csrpan; system32\DRIVERS\csrpan.sys [X]
S3 csrserial; system32\DRIVERS\csrserial.sys [X]
S3 csrusb; System32\Drivers\csrusb.sys [X]
S3 e1cexpress; system32\DRIVERS\e1c62x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 GPUZ; \??\C:\Windows\TEMP\GPUZ.sys [X]
S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-07-22 21:09 - 2014-07-22 21:09 - 00000000 ___RD () C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-22 18:22 - 2014-07-22 18:22 - 00001132 _____ () C:\Users\**********\Desktop\checkup.txt
2014-07-22 13:51 - 2014-07-22 13:50 - 02347384 _____ (ESET) C:\Users\**********\Desktop\esetsmartinstaller_deu.exe
2014-07-22 13:51 - 2014-07-22 13:50 - 00854390 _____ () C:\Users\**********\Desktop\SecurityCheck.exe
2014-07-21 20:45 - 2014-07-21 21:20 - 00001182 _____ () C:\Users\**********\Desktop\JRT.txt
2014-07-21 20:41 - 2014-07-21 20:41 - 00000000 ____D () C:\Windows\ERUNT
2014-07-21 20:39 - 2014-07-21 21:34 - 00005235 _____ () C:\Users\**********\Desktop\AdwCleaner[S0].txt
2014-07-21 20:39 - 2014-07-21 21:34 - 00001145 _____ () C:\Users\**********\Desktop\AdwCleaner[S1].txt
2014-07-21 20:29 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-21 20:28 - 2014-07-21 20:36 - 00000000 ____D () C:\AdwCleaner
2014-07-21 20:25 - 2014-07-21 20:24 - 01354223 _____ () C:\Users\**********\Desktop\adwcleaner_3.216.exe
2014-07-21 20:22 - 2014-07-21 20:24 - 00003991 _____ () C:\Users\**********\Desktop\mbam.txt
2014-07-21 20:11 - 2014-07-21 20:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 20:11 - 2014-07-21 20:11 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 20:11 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-21 20:11 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-21 20:11 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-21 13:59 - 2014-07-21 13:59 - 00049185 _____ () C:\ComboFix.txt
2014-07-21 13:30 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-07-21 13:30 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-07-21 13:30 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-07-21 13:30 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-07-21 13:23 - 2014-07-21 14:00 - 00000000 ____D () C:\Qoobox
2014-07-21 13:22 - 2014-07-21 20:18 - 00000000 ____D () C:\Windows\erdnt
2014-07-21 13:22 - 2014-07-21 13:21 - 05561612 ____R (Swearware) C:\Users\**********\Desktop\ComboFix.exe
2014-07-20 22:32 - 2014-07-19 00:17 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\**********\Desktop\tdsskiller.exe
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS4Tool
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\Program Files (x86)\DSDCS
2014-07-19 23:38 - 2014-07-19 23:38 - 00001228 _____ () C:\Users\**********\Desktop\Revo Uninstaller.lnk
2014-07-19 23:38 - 2014-07-19 23:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-19 12:53 - 2014-07-19 02:41 - 00040610 _____ () C:\Users\**********\Desktop\Logfiles.rar
2014-07-19 02:32 - 2014-07-19 02:39 - 00000000 ____D () C:\Users\**********\Desktop\Neuer Ordner (3)
2014-07-19 01:26 - 2014-07-22 21:40 - 00000000 ____D () C:\FRST
2014-07-19 01:21 - 2014-07-19 01:21 - 00000000 ____D () C:\found.005
2014-07-19 01:17 - 2014-07-19 01:17 - 00000020 _____ () C:\Users\**********\defogger_reenable
2014-07-18 23:14 - 2014-07-18 23:14 - 00000000 ____D () C:\found.004
2014-07-17 14:13 - 2014-07-17 14:13 - 00000967 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2014-07-17 14:09 - 2014-07-17 14:09 - 00301200 _____ () C:\Windows\Minidump\071714-10779-01.dmp
2014-07-17 14:08 - 2014-07-17 14:08 - 00000000 ____D () C:\found.003
2014-07-16 19:48 - 2014-07-16 19:48 - 00009568 _____ () C:\Users\**********\Desktop\002.txt
2014-07-16 19:47 - 2014-07-16 19:47 - 00001828 _____ () C:\Users\**********\Desktop\001.txt
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Program Files (x86)\NirSoft
2014-07-16 17:06 - 2014-07-16 17:06 - 00293456 _____ () C:\Windows\Minidump\071614-14133-01.dmp
2014-07-16 17:05 - 2014-07-16 17:05 - 00000000 ____D () C:\found.002
2014-07-16 16:52 - 2014-07-16 16:52 - 00262144 _____ () C:\Windows\Minidump\071614-11076-01.dmp
2014-07-16 16:51 - 2014-07-16 16:51 - 00000000 ____D () C:\found.001
2014-07-10 15:29 - 2014-07-19 13:26 - 00000000 ____D () C:\Users\**********\AppData\Local\Arma 3
2014-07-10 15:29 - 2014-07-17 15:25 - 00000000 ____D () C:\Users\**********\Eigene Dokumente\Arma 3
2014-07-10 15:29 - 2014-07-10 15:29 - 00000000 ____D () C:\ProgramData\Bohemia Interactive
2014-07-09 12:19 - 2014-06-30 04:09 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-09 12:19 - 2014-06-30 04:04 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-09 12:19 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-09 12:19 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-09 12:19 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-09 12:19 - 2014-06-06 12:10 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-09 12:19 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-09 12:19 - 2014-05-30 10:08 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-07-09 12:19 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-07-09 12:19 - 2014-05-30 08:45 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-09 12:18 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-09 12:18 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-09 12:18 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-09 12:18 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-09 12:18 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-09 12:18 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-09 12:18 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-09 12:18 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-09 12:18 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-09 12:18 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-09 12:18 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-09 12:18 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-09 12:18 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-09 12:18 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-09 12:18 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-09 12:18 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-09 12:18 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-09 12:18 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-09 12:18 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-09 12:18 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-09 12:18 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-09 12:18 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-09 12:18 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-09 12:18 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-09 12:18 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-09 12:18 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-09 12:18 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-09 12:18 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-09 12:18 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-09 12:18 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-09 12:18 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-09 12:18 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-09 12:18 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-09 12:18 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-09 12:18 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-09 12:18 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-09 12:18 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-09 12:18 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-09 12:18 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-09 12:18 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-09 12:18 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-09 12:18 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-09 12:18 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-09 12:18 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-09 12:18 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-09 12:18 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-09 12:18 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-09 12:18 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-09 12:18 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-09 12:18 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-09 12:18 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-09 12:18 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-09 12:18 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-09 12:18 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-09 12:18 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-09 12:18 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-09 12:18 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-09 12:18 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-09 12:18 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-09 12:13 - 2012-03-12 19:26 - 00001386 _____ () C:\Users\**********\Desktop\Skype.lnk
2014-07-07 09:08 - 2014-07-07 09:08 - 00003246 _____ () C:\Windows\System32\Tasks\SamsungMagician
2014-07-07 09:08 - 2014-07-07 09:08 - 00001067 _____ () C:\Users\Public\Desktop\Samsung Magician.lnk
2014-07-07 09:08 - 2014-07-07 09:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2014-07-06 23:52 - 2014-04-18 17:02 - 00129472 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzDxgk.sys
2014-07-06 23:52 - 2014-04-18 17:02 - 00074432 _____ (Razer, Inc.) C:\Windows\system32\Drivers\RzFilter.sys
2014-07-06 23:34 - 2014-07-17 20:42 - 00001926 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-06 23:34 - 2014-07-06 23:34 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-06 23:29 - 2014-07-06 23:26 - 00237764 _____ () C:\Users\**********\Desktop\WER-21122-0.sysdata.xml
2014-07-06 23:28 - 2014-07-06 23:28 - 00001014 _____ () C:\Users\**********\Desktop\Minidump - Verknüpfung.lnk
2014-07-06 23:26 - 2014-07-06 23:26 - 00301232 _____ () C:\Windows\Minidump\070614-10452-01.dmp
2014-07-06 23:18 - 2014-07-06 23:18 - 00000000 ____D () C:\found.000
2014-07-01 23:45 - 2014-07-02 00:00 - 00000000 ____D () C:\Users\**********\AppData\Roaming\SpinTires
2014-07-01 23:44 - 2014-07-01 23:44 - 00000650 _____ () C:\Users\**********\Desktop\Spintires.lnk
2014-07-01 23:44 - 2014-07-01 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spintires
2014-06-28 02:21 - 2014-06-28 02:21 - 00000000 ____D () C:\Users\**********\AppData\Local\Sniper3
2014-06-25 20:30 - 2014-06-25 20:30 - 00000000 ____D () C:\Program Files\Microsoft Xbox One Controller for Windows
2014-06-24 03:09 - 2014-06-24 03:09 - 00000000 ____D () C:\Users\**********\AppData\Local\Oblivion
2014-06-24 03:06 - 2014-06-24 03:06 - 00001328 _____ () C:\Users\**********\Desktop\The Elder Scrolls Morrowind Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001311 _____ () C:\Users\**********\Desktop\The Elder Scrolls Oblivion Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001294 _____ () C:\Users\**********\Desktop\The Elder Scrolls Skyrim Legendary Edition Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001283 _____ () C:\Users\**********\Desktop\The Elder Scrolls Morrowind Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001271 _____ () C:\Users\**********\Desktop\The Elder Scrolls Oblivion Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001240 _____ () C:\Users\**********\Desktop\The Elder Scrolls Skyrim Legendary Edition.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001232 _____ () C:\Users\**********\Desktop\The Elder Scrolls Daggerfall.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001193 _____ () C:\Users\**********\Desktop\The Elder Scrolls Arena.lnk
2014-06-24 02:31 - 2014-06-24 02:31 - 00000000 __SHD () C:\ProgramData\SecuROM

==================== One Month Modified Files and Folders =======

2014-07-22 21:40 - 2014-07-19 01:26 - 00000000 ____D () C:\FRST
2014-07-22 21:29 - 2011-12-17 02:03 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-22 21:15 - 2009-07-14 06:45 - 00032688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-22 21:15 - 2009-07-14 06:45 - 00032688 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-22 21:14 - 2010-11-21 08:50 - 00699594 _____ () C:\Windows\system32\perfh007.dat
2014-07-22 21:14 - 2010-11-21 08:50 - 00153862 _____ () C:\Windows\system32\perfc007.dat
2014-07-22 21:14 - 2009-07-14 07:13 - 01649420 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-22 21:10 - 2011-12-17 02:03 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-22 21:09 - 2014-07-22 21:09 - 00000000 ___RD () C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-22 21:09 - 2014-05-15 18:20 - 00000000 ____D () C:\Users\**********\AppData\Roaming\DropboxMaster
2014-07-22 21:09 - 2013-01-14 16:37 - 00000000 ____D () C:\Users\**********\AppData\Roaming\Dropbox
2014-07-22 21:08 - 2014-03-14 15:52 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-22 21:08 - 2014-03-06 08:57 - 00094728 _____ () C:\Windows\setupact.log
2014-07-22 21:08 - 2013-07-20 14:35 - 00000043 _____ () C:\Windows\MezzmoMediaServer.INI
2014-07-22 21:08 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-22 18:34 - 2011-12-16 20:04 - 01471186 _____ () C:\Windows\WindowsUpdate.log
2014-07-22 18:26 - 2014-03-06 08:57 - 00168074 _____ () C:\Windows\PFRO.log
2014-07-22 18:22 - 2014-07-22 18:22 - 00001132 _____ () C:\Users\**********\Desktop\checkup.txt
2014-07-22 17:56 - 2012-10-04 18:34 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-22 17:02 - 2011-12-26 14:45 - 00000000 ___RD () C:\Users\**********\Meine Freigaben
2014-07-22 13:50 - 2014-07-22 13:51 - 02347384 _____ (ESET) C:\Users\**********\Desktop\esetsmartinstaller_deu.exe
2014-07-22 13:50 - 2014-07-22 13:51 - 00854390 _____ () C:\Users\**********\Desktop\SecurityCheck.exe
2014-07-22 03:26 - 2011-12-20 06:10 - 00000000 ____D () C:\Users\**********\AppData\Roaming\Skype
2014-07-22 01:29 - 2011-12-18 02:52 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{01D039A5-45B5-4A9C-AC86-320D09BCFF9A}
2014-07-21 21:34 - 2014-07-21 20:39 - 00005235 _____ () C:\Users\**********\Desktop\AdwCleaner[S0].txt
2014-07-21 21:34 - 2014-07-21 20:39 - 00001145 _____ () C:\Users\**********\Desktop\AdwCleaner[S1].txt
2014-07-21 21:20 - 2014-07-21 20:45 - 00001182 _____ () C:\Users\**********\Desktop\JRT.txt
2014-07-21 20:41 - 2014-07-21 20:41 - 00000000 ____D () C:\Windows\ERUNT
2014-07-21 20:36 - 2014-07-21 20:28 - 00000000 ____D () C:\AdwCleaner
2014-07-21 20:35 - 2011-12-17 15:14 - 00000000 ____D () C:\Users\**********\AppData\Local\CrashDumps
2014-07-21 20:24 - 2014-07-21 20:25 - 01354223 _____ () C:\Users\**********\Desktop\adwcleaner_3.216.exe
2014-07-21 20:24 - 2014-07-21 20:22 - 00003991 _____ () C:\Users\**********\Desktop\mbam.txt
2014-07-21 20:21 - 2014-07-21 20:11 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-21 20:18 - 2014-07-21 13:22 - 00000000 ____D () C:\Windows\erdnt
2014-07-21 20:11 - 2014-07-21 20:11 - 00001066 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-21 20:11 - 2014-07-21 20:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2014-07-21 14:00 - 2014-07-21 13:23 - 00000000 ____D () C:\Qoobox
2014-07-21 13:59 - 2014-07-21 13:59 - 00049185 _____ () C:\ComboFix.txt
2014-07-21 13:52 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-07-21 13:51 - 2009-07-14 04:34 - 75497472 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 30932992 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 05242880 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-07-21 13:51 - 2009-07-14 04:34 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-07-21 13:21 - 2014-07-21 13:22 - 05561612 ____R (Swearware) C:\Users\**********\Desktop\ComboFix.exe
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DS4Tool
2014-07-20 22:25 - 2014-07-20 22:25 - 00000000 ____D () C:\Program Files (x86)\DSDCS
2014-07-20 22:25 - 2014-06-14 01:13 - 00000987 _____ () C:\Users\Public\Desktop\DS4Tool.lnk
2014-07-20 22:25 - 2014-06-14 01:12 - 00000000 ____D () C:\Users\**********\AppData\Roaming\DSDCS
2014-07-20 01:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-07-19 23:38 - 2014-07-19 23:38 - 00001228 _____ () C:\Users\**********\Desktop\Revo Uninstaller.lnk
2014-07-19 23:38 - 2014-07-19 23:38 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-19 13:26 - 2014-07-10 15:29 - 00000000 ____D () C:\Users\**********\AppData\Local\Arma 3
2014-07-19 02:44 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-19 02:42 - 2011-12-23 21:19 - 00000000 ____D () C:\Windows\Minidump
2014-07-19 02:42 - 2011-12-16 20:00 - 00303938 ____N () C:\Windows\Minidump\071914-10389-01.dmp
2014-07-19 02:41 - 2014-07-19 12:53 - 00040610 _____ () C:\Users\**********\Desktop\Logfiles.rar
2014-07-19 02:39 - 2014-07-19 02:32 - 00000000 ____D () C:\Users\**********\Desktop\Neuer Ordner (3)
2014-07-19 01:21 - 2014-07-19 01:21 - 00000000 ____D () C:\found.005
2014-07-19 01:17 - 2014-07-19 01:17 - 00000020 _____ () C:\Users\**********\defogger_reenable
2014-07-19 01:17 - 2011-12-16 20:04 - 00000000 ____D () C:\Users\**********
2014-07-19 00:17 - 2014-07-20 22:32 - 04181856 _____ (Kaspersky Lab ZAO) C:\Users\**********\Desktop\tdsskiller.exe
2014-07-18 23:40 - 2014-03-18 09:43 - 00000000 _____ () C:\Windows\System32\Tasks\MSIAfterburner
2014-07-18 23:16 - 2014-04-04 08:33 - 00495484 _____ () C:\Windows\DPINST.LOG
2014-07-18 23:15 - 2011-12-16 20:00 - 00303910 ____N () C:\Windows\Minidump\071814-10561-01.dmp
2014-07-18 23:14 - 2014-07-18 23:14 - 00000000 ____D () C:\found.004
2014-07-18 12:05 - 2014-03-16 01:39 - 00000000 ____D () C:\Program Files (x86)\MSI Afterburner
2014-07-18 10:31 - 2013-09-15 22:37 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-07-17 20:42 - 2014-07-06 23:34 - 00001926 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-07-17 15:25 - 2014-07-10 15:29 - 00000000 ____D () C:\Users\**********\Eigene Dokumente\Arma 3
2014-07-17 14:13 - 2014-07-17 14:13 - 00000967 _____ () C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2014-07-17 14:13 - 2011-12-17 03:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2014-07-17 14:09 - 2014-07-17 14:09 - 00301200 _____ () C:\Windows\Minidump\071714-10779-01.dmp
2014-07-17 14:09 - 2014-03-14 15:23 - 666796358 _____ () C:\Windows\MEMORY.DMP
2014-07-17 14:08 - 2014-07-17 14:08 - 00000000 ____D () C:\found.003
2014-07-16 19:48 - 2014-07-16 19:48 - 00009568 _____ () C:\Users\**********\Desktop\002.txt
2014-07-16 19:47 - 2014-07-16 19:47 - 00001828 _____ () C:\Users\**********\Desktop\001.txt
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2014-07-16 19:44 - 2014-07-16 19:44 - 00000000 ____D () C:\Program Files (x86)\NirSoft
2014-07-16 17:06 - 2014-07-16 17:06 - 00293456 _____ () C:\Windows\Minidump\071614-14133-01.dmp
2014-07-16 17:05 - 2014-07-16 17:05 - 00000000 ____D () C:\found.002
2014-07-16 16:52 - 2014-07-16 16:52 - 00262144 _____ () C:\Windows\Minidump\071614-11076-01.dmp
2014-07-16 16:51 - 2014-07-16 16:51 - 00000000 ____D () C:\found.001
2014-07-11 11:14 - 2014-03-16 01:39 - 00001050 _____ () C:\Users\**********\Desktop\MSI Afterburner.lnk
2014-07-10 15:29 - 2014-07-10 15:29 - 00000000 ____D () C:\ProgramData\Bohemia Interactive
2014-07-10 15:29 - 2014-03-20 11:32 - 00000000 ___RD () C:\Users\**********\Eigene Dokumente
2014-07-10 15:29 - 2014-03-11 11:55 - 00153422 _____ () C:\Windows\DirectX.log
2014-07-09 21:47 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-07-09 19:23 - 2009-07-14 06:45 - 00335488 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-09 19:22 - 2014-05-07 00:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-09 19:22 - 2010-11-21 09:00 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-09 19:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-09 19:22 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-09 16:26 - 2013-08-15 12:47 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-09 16:26 - 2011-12-19 21:02 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 01:56 - 2012-10-04 18:34 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-09 01:56 - 2012-04-03 19:41 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 01:56 - 2011-12-17 04:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-08 12:29 - 2012-07-12 19:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-07-07 09:08 - 2014-07-07 09:08 - 00003246 _____ () C:\Windows\System32\Tasks\SamsungMagician
2014-07-07 09:08 - 2014-07-07 09:08 - 00001067 _____ () C:\Users\Public\Desktop\Samsung Magician.lnk
2014-07-07 09:08 - 2014-07-07 09:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2014-07-07 09:08 - 2014-03-02 05:04 - 00000000 ____D () C:\Program Files (x86)\Samsung Magician
2014-07-06 23:52 - 2013-10-26 14:09 - 00000000 ____D () C:\Windows\Razer Core
2014-07-06 23:52 - 2013-08-18 01:12 - 00000000 ____D () C:\ProgramData\Razer
2014-07-06 23:52 - 2012-01-27 19:26 - 00000000 ____D () C:\Program Files (x86)\Razer
2014-07-06 23:51 - 2011-12-16 20:10 - 00069432 _____ () C:\Users\**********\AppData\Local\GDIPFONTCACHEV1.DAT
2014-07-06 23:50 - 2012-01-27 19:33 - 00000000 ____D () C:\Users\**********\AppData\Local\Razer
2014-07-06 23:49 - 2012-01-27 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2014-07-06 23:34 - 2014-07-06 23:34 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-07-06 23:34 - 2014-04-19 20:37 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-07-06 23:34 - 2013-12-19 08:52 - 00092008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 01041168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00427360 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00224896 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-07-06 23:34 - 2013-09-15 22:37 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-07-06 23:34 - 2011-12-17 02:03 - 00307344 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-07-06 23:28 - 2014-07-06 23:28 - 00001014 _____ () C:\Users\**********\Desktop\Minidump - Verknüpfung.lnk
2014-07-06 23:26 - 2014-07-06 23:29 - 00237764 _____ () C:\Users\**********\Desktop\WER-21122-0.sysdata.xml
2014-07-06 23:26 - 2014-07-06 23:26 - 00301232 _____ () C:\Windows\Minidump\070614-10452-01.dmp
2014-07-06 23:18 - 2014-07-06 23:18 - 00000000 ____D () C:\found.000
2014-07-02 00:00 - 2014-07-01 23:45 - 00000000 ____D () C:\Users\**********\AppData\Roaming\SpinTires
2014-07-01 23:44 - 2014-07-01 23:44 - 00000650 _____ () C:\Users\**********\Desktop\Spintires.lnk
2014-07-01 23:44 - 2014-07-01 23:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spintires
2014-06-30 08:45 - 2014-05-25 12:18 - 00000000 ____D () C:\Users\**********\AppData\Roaming\DS4Tool
2014-06-30 04:09 - 2014-07-09 12:19 - 00519168 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 04:04 - 2014-07-09 12:19 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-28 02:21 - 2014-06-28 02:21 - 00000000 ____D () C:\Users\**********\AppData\Local\Sniper3
2014-06-25 20:56 - 2014-03-20 11:33 - 00000000 ____D () C:\Users\**********\Eigene Dokumente\My Games
2014-06-25 20:56 - 2012-02-04 10:36 - 00000000 ____D () C:\ProgramData\Codemasters
2014-06-25 20:30 - 2014-06-25 20:30 - 00000000 ____D () C:\Program Files\Microsoft Xbox One Controller for Windows
2014-06-25 19:36 - 2013-09-19 00:52 - 00000216 _____ () C:\Users\**********\d3d_antilag.log
2014-06-25 19:34 - 2014-03-20 11:33 - 00006583 _____ () C:\Users\**********\Eigene Dokumente\TombRaider.log
2014-06-24 03:35 - 2012-01-18 13:58 - 00000000 ____D () C:\Users\**********\AppData\Local\Origin
2014-06-24 03:35 - 2012-01-18 13:58 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-06-24 03:35 - 2011-12-17 23:00 - 00000000 ____D () C:\ProgramData\Origin
2014-06-24 03:09 - 2014-06-24 03:09 - 00000000 ____D () C:\Users\**********\AppData\Local\Oblivion
2014-06-24 03:09 - 2012-02-02 01:24 - 00000000 ____D () C:\Users\**********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2014-06-24 03:06 - 2014-06-24 03:06 - 00001328 _____ () C:\Users\**********\Desktop\The Elder Scrolls Morrowind Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001311 _____ () C:\Users\**********\Desktop\The Elder Scrolls Oblivion Game of the Year Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001294 _____ () C:\Users\**********\Desktop\The Elder Scrolls Skyrim Legendary Edition Launcher.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001283 _____ () C:\Users\**********\Desktop\The Elder Scrolls Morrowind Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001271 _____ () C:\Users\**********\Desktop\The Elder Scrolls Oblivion Game of the Year.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001240 _____ () C:\Users\**********\Desktop\The Elder Scrolls Skyrim Legendary Edition.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001232 _____ () C:\Users\**********\Desktop\The Elder Scrolls Daggerfall.lnk
2014-06-24 03:06 - 2014-06-24 03:06 - 00001193 _____ () C:\Users\**********\Desktop\The Elder Scrolls Arena.lnk
2014-06-24 02:31 - 2014-06-24 02:31 - 00000000 __SHD () C:\ProgramData\SecuROM
2014-06-23 21:39 - 2014-03-20 11:33 - 00000000 ____D () C:\Users\**********\Eigene Dokumente\ArcheAge
2014-06-23 21:35 - 2014-04-02 16:34 - 00000000 ____D () C:\ArcheAge
2014-06-23 21:32 - 2014-04-11 15:09 - 00000000 ____D () C:\Program Files (x86)\Glyph
2014-06-22 22:38 - 2013-03-11 22:36 - 00000000 ____D () C:\Users\**********\AppData\Roaming\vlc

Some content of TEMP:
====================
C:\Users\**********\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpmhlgdk.dll
C:\Users\**********\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-07-19 23:37

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 23.07.2014, 11:35   #22
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Java und Adobe updaten. Avast neu installieren. Den Käse auf Laufwerk E und F löschen.

Downloade Dir bitte TFC ( von Oldtimer ) und speichere die Datei auf dem Desktop.
Schließe nun alle offenen Programme und trenne Dich von dem Internet.
Doppelklick auf die TFC.exe und drücke auf Start.
Sollte TFC nicht alle Dateien löschen können wird es einen Neustart verlangen. Dies bitte zulassen.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.07.2014, 19:51   #23
pilimen400
 
Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Avast neu installiert, Java u. Adobe geupdatet, den Käse auf E u. F gelöscht.

TFC ausgeführt (ist 2 mal abgestürzt, beim 3. Versuch hat es bis zum Ende geklappt).

Avast läuft, bis jetzt zumindest keine Bluescreens mehr. Es scheint, als ob alles wieder normal läuft!

Sind wir nun fertig?

Und noch was: Habt ihr hier irgendwo eine Anleitung, wie man sein System optimal präventiv gegen solche Angriffe schützt? Aktuell läuft bei mir nur die Win7 Firewall, Avast u. Spybot im Hintergrund und hin und wieder (ca. alle 30 Tage) lasse ich Avast und Spybot die Daten durchlaufen.

Alt 24.07.2014, 19:00   #24
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



kommt jetzt:

Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 25.07.2014, 13:35   #25
pilimen400
 
Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Gestern ist der PC wieder abgestürzt. Chrome, Steam war an und ich habe ca. 20 GB von der SD Karte auf die C: SSD kopiert - NTFS.SYS war der auslöser.
Später ist der PC noch mal beim herunterfahren abgestürzt - NDProxy.SYS war der auslöser.

Heute arbeitet der PC unter Windows relativ langsam und auch im Internet ist er verdächtig lahm.

Kann ich ab jetzt einen Trojaner etc. ausschließen?

Alt 26.07.2014, 08:04   #26
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Ja kannst Du. Das klingt für mich eher nach Treiber oder Hardware.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 27.07.2014, 12:23   #27
pilimen400
 
Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Gut, dann schaue ich mal, was da noch los ist mit meinem System.
Danke noch mal für den Einsatz!

Habe dann keine Fragen mehr.

Alt 27.07.2014, 14:17   #28
schrauber
/// the machine
/// TB-Ausbilder
 

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - Standard

Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren
bluescreen, onedrive, pup.optional.bundleinstaller.a, pup.optional.ciuvo.a, pup.optional.conduit.a, pup.optional.opencandy, pup.optional.opinionsquare.a, pup.optional.regcleanpro.a, pup.optional.softonic.a, pup.optional.trovi, pup.optional.trovi.a, smartphone, win32/amonetize.bi, win32/conduit.searchprotect.n, win32/conduit.searchprotect.p, win32/downloadsponsor.a, win32/downware.l, win32/hacktool.cheatengine.ab, win32/hacktool.crack.bl, win32/keygen.ad, win32/packed.vmprotect.abd, win32/remoteadmin.netcat, win32/toolbar.conduit.ac, win32/toolbar.conduit.ah, win32/toolbar.widdit.a, win32/toolbar.widgi, zurückgesetzt




Ähnliche Themen: Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren


  1. Microsoft Security Essentials lässt sich nicht mehr aktivieren.
    Plagegeister aller Art und deren Bekämpfung - 15.11.2015 (43)
  2. (Vista) Sicherheitscenter lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 24.12.2014 (3)
  3. Sicherheitscenter lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 12.07.2014 (7)
  4. Antivirenprogramm lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 10.05.2014 (34)
  5. Win XP Malware Funde, Antivir lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 03.04.2014 (15)
  6. AVAST wurde deaktiviert und lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 11.11.2013 (25)
  7. Avast Free deaktiviert, lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 11.02.2013 (7)
  8. Avast lässt sich nicht mehr aktivieren - RPC-Fehler durch Wurm?
    Plagegeister aller Art und deren Bekämpfung - 07.02.2013 (15)
  9. Rootkit / Echtzeitscanner lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 11.09.2012 (11)
  10. AV Software lässt sich nicht mehr installieren und Firewall nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 06.09.2012 (7)
  11. Firewall inaktiv und lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 26.02.2012 (14)
  12. Firewall inaktiv und lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 04.11.2011 (31)
  13. Virenprogramm lässt sich nicht mehr aktivieren + Pc hängt sich auf
    Plagegeister aller Art und deren Bekämpfung - 19.03.2011 (10)
  14. Windows Sicherheitscenter lässt sich nicht mehr aktivieren, die zweite
    Plagegeister aller Art und deren Bekämpfung - 08.03.2011 (2)
  15. Windows-Sicherheitscenter lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 02.03.2011 (15)
  16. avira plötzlich nicht mehr aktiv und lässt sich nicht mehr aktivieren
    Plagegeister aller Art und deren Bekämpfung - 24.12.2009 (13)
  17. Norten Auto Protect lässt sich nicht mehr aktivieren
    Log-Analyse und Auswertung - 20.02.2006 (1)

Zum Thema Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren - hi, Scan mit Combofix WARNUNG an die MITLESER: Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde! Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link WICHTIG: Speichere - Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren...
Archiv
Du betrachtest: Win 7: PC Neustart (Bluescreen) + Avast lässt sich nicht mehr aktivieren auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.